Boomerang for Gmail
The AI review rates the findings as likely false positive, but the risk score (78/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.9.6
- Artifact
- SHA256 AD1…2C5
- Source
- Findings (non-IoC)
Is Boomerang for Gmail safe?
Boomerang for Gmail is a popular email management and meeting scheduling tool. The extension uses standard permissions to interact with your inbox and communicate with its own servers, specifically reaching out to baydin.com, which is the official domain of the company that builds it. The files inside the extension, such as background.js and various b4g_bookmarklet files, handle the core scheduling and tracking features you expect from this tool.
Security scanners flagged several items in the code, including a unicode-heavy obfuscation alert and a supply chain malware signature. The obfuscation alerts come from the bookmarklet files, which use unicode characters by design so they can be safely dragged into your browser bookmarks without breaking. The malware signature matched a rule looking for source maps attached to bundled code, which is just a normal byproduct of how modern JavaScript is compiled and has nothing to do with actual malware.
The vast majority of the other warnings are scanner errors. The system extracted hundreds of supposed network domains, but these are actually just internal code variables being misread as web addresses. Because the extension is communicating with its legitimate corporate domain and the flagged code patterns are standard build artifacts, the warnings do not reflect any real threat to your browser or your data.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 6 | b4g_bookmarklet_1.9.4.jsb4g_bookmarklet_1.9.3.jsb4g_bookmarklet_1.9.6.js +3 more | - |
Publisher Evidence
Limited evidenceBaydin Inc.
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
1 rule(6 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Boomerang for Gmail is a widely used email management and meeting scheduling tool. The extension codebase includes b4g.js, background.js, and multiple versions of b4g_bookmarklet files, which align directly with its core functionality of managing email scheduling and providing bookmarklet utilities. The network endpoints extracted from the bundle include baydin.com, the legitimate corporate domain for the company that develops Boomerang. The two network fetch findings, NET-FETCH-b4g.js-79 and NET-FETCH-background.js-210, represent standard background communication with the extension servers rather than suspicious external data transmission.
The scan flagged six high-severity malware signatures using the YARA--supply_chain_sourcemap_appended_iife rule across the b4g_bookmarklet files. This specific rule triggers when a source map is appended to an Immediately Invoked Function Expression. In modern JavaScript development, bundlers frequently append source maps to IIFEs to aid in debugging minified code. This is a standard build artifact, not an indicator of a compromised supply chain or injected malware payload.
The scanner also flagged OBFUSCATION-unicode_heavy in background.js and the bookmarklet files. Bookmarklets inherently rely on URL-encoded or unicode-escaped characters to function correctly when dragged into a browser bookmarks bar. This legitimate design choice naturally triggers unicode-heavy obfuscation detectors. Furthermore, the 390 extracted IoCs are almost entirely false positives. The IoC extractor misidentified CSS and jQuery property access chains, such as 0-this.offset.relative.top-this.offset.parent.top and b4g-button.blue, as network domains. These are internal JavaScript object references, not external infrastructure.
Looking closely at the extracted network endpoints, the IoC extractor captured strings like addtimebutton.show, announcementel.show, and api.helper.get.email. These are clearly DOM element selectors and internal API helper functions being parsed as domain names. When a scanner flags hundreds of IoCs, the nature of those indicators matters far more than the raw count. In this case, every single suspicious domain is either a legitimate corporate asset or a mangled piece of frontend code.
A skeptic might point to the empty developer name in the metadata and the high volume of code-smell findings as evidence of a repackaged or malicious clone. However, the presence of the specific baydin.com endpoint and the exact file naming conventions strongly indicate this is the authentic extension. The empty developer field is a metadata extraction artifact from the Edge store scrape. The 124 code-smell findings are low-severity noise typical of any large, bundled JavaScript application. The actual network requests are standard fetch calls for a productivity tool communicating with its own backend, confirming the extension behaves exactly as advertised.
Key Reasons
- Network endpoints include baydin.com, the legitimate corporate domain for Boomerang.
- Malware signatures match a benign YARA rule for source maps appended to IIFEs.
- Obfuscation findings are caused by legitimate unicode encoding in bookmarklet files.
- IoC extractor misidentified JavaScript property chains and CSS selectors as network domains.
False Positive Considerations
- IoC extractor misidentifying JavaScript property chains as domains
- YARA rule matching benign source maps appended to IIFEs
- Unicode encoding in bookmarklets triggering obfuscation detectors
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 92%.
Edge version history
Risk trend by version
6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace