Google Translate in Side Panel
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 3 weeks ago
- Version
- v5.3.6
- Artifact
- SHA256 DE2…10E
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 2 | chunks/useTheme-lHWnO_PU.jscontent-scripts/content.js | - |
| LOW | postinstall persistence mechanism | 7 | content-scripts/ai-chat.jschunks/useTheme-lHWnO_PU.jscontent-scripts/slash-command-iframe.js +4 more | - |
| LOW | postinstall crypto operations | 7 | chunks/useTheme-lHWnO_PU.jscontent-scripts/ai-chat.jscontent-scripts/slash-command-iframe.js +4 more | - |
| LOW | OriginsNotVerified | 3 | content-scripts/content.jschunks/useTheme-lHWnO_PU.jscontent-scripts/web-translate.js | - |
| LOW | postinstall file manipulation | 8 | chunks/options-cxsUWObe.jschunks/useTheme-lHWnO_PU.jschunks/textarea-BlpghVKu.js +5 more | - |
| LOW | postinstall system command | 12 | content-scripts/content.jschunks/options-cxsUWObe.jscontent-scripts/web-translate.js +9 more | - |
| LOW | postinstall environment access | 11 | chunks/sidepanel-__p9isCL.jschunks/traffic-CLkrk4J9.jschunks/file-text-RjVxHXpD.js +8 more | - |
| LOW | postinstall obfuscation | 6 | chunks/useTheme-lHWnO_PU.jschunks/textarea-BlpghVKu.jscontent-scripts/ai-chat.js +3 more | - |
| LOW | postinstall network communication | 9 | chunks/options-cxsUWObe.jsbackground.jschunks/useTheme-lHWnO_PU.js +6 more | - |
| LOW | LocalStorageShouldNotBeUsed | 2 | chunks/useTheme-lHWnO_PU.jscontent-scripts/content.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 3 | chunks/useTheme-lHWnO_PU.jscontent-scripts/slash-command-iframe.jscontent-scripts/content.js | - |
| LOW | postinstall file download | 8 | chunks/textarea-BlpghVKu.jscontent-scripts/ai-chat.jschunks/useTheme-lHWnO_PU.js +5 more | - |
| LOW | SQLInjection | 1 | chunks/options-cxsUWObe.js | - |
| LOW | NoUseWeakRandom | 5 | content-scripts/ai-chat.jschunks/useTheme-lHWnO_PU.jscontent-scripts/slash-command-iframe.js +2 more | - |
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
14 rules(84 hits)Requested Permissions
20 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This translation extension presents a classic false-positive scenario driven by automated detection of normal network activity. The findings_summary explicitly shows zero malware signatures, zero IoC matches, zero obfuscation detections, and zero code-smell findings. All 8 findings are medium-severity network detections that simply flag the presence of fetch() calls in standard files.
The network findings appear in expected locations for a translation extension: background.js handles service worker logic, content-scripts/content.js injects functionality into web pages, and chunks/sidepanel-Bc6kV6r-.js and chunks/useTheme-CTIIRX43.js are webpack-bundled module files with hashed names. These fetch calls are necessary for the extension to communicate with translation APIs and load resources. The findings do not reveal specific destination domains—only that fetch() exists—which is insufficient evidence of malicious behavior.
The extension's description "Google Translate in your browser side panel" aligns with the code structure showing sidepanel functionality and content scripts, consistent with legitimate translation tools. The webpack chunk naming pattern (Bc6kV6r-, CTIIRX43) is standard build output, not obfuscation. The findings_summary confirms obfuscation count is zero.
Counterargument: The developer uses a generic Gmail address ([email protected]) rather than a verified organization account, which could indicate an impersonation attempt or untrustworthy publisher. However, developer email type alone cannot establish malicious intent. Legitimate extensions frequently use personal Gmail addresses, especially for smaller projects. Without corroborating evidence—malware signatures, suspicious domains, credential theft patterns, or obfuscation—the email address is insufficient to override the absence of actual threat indicators. The 100,000 user count further suggests the extension has operated without reported compromise.
The extension exhibits no high-confidence threat indicators: no typosquatting of well-known extensions, no browser hijacking domains, no credential theft patterns, no malware delivery mechanisms, and no proxyware functionality. The findings are entirely consistent with benign translation software making legitimate API requests.
Key Reasons
- Zero malware signatures detected in findings_summary
- Zero suspicious IoC domains extracted from code
- Zero obfuscation or code-smell findings
- Network findings are generic fetch() calls without suspicious destinations
- Webpack chunk files show standard bundler output, not obfuscation
False Positive Considerations
- Generic fetch() network calls flagged as medium severity
- Webpack bundle chunks with hashed filenames
- No actual threat indicators present despite 8 total findings
Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 85%.
Chrome version history
Risk trend by version
10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
XB, block all ads
[email protected]
Zent Translate
[email protected]
Pinterest Image Downloader | Futoo
[email protected]
YT Subtitle - Video Summarizer & Translator
[email protected]
gTab
[email protected]
ChatGPT Sidebar
[email protected]