Dark Reader
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v4.9.133
- Artifact
- SHA256 EB0…3AB
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceDark Reader Ltd
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
6 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category typosquatting; evidence quality moderate.
This extension presents a significant typosquatting concern. The name "Dark Reader" exactly matches a well-established, popular dark mode extension that is legitimately published by Dark Reader Ltd with millions of users across browser stores. However, this listing shows an empty developer name field, which is inconsistent with the legitimate Dark Reader extension that clearly attributes its developer.
The extension requests manifest permissions including 'tabs' and '
Critically, there are zero malware signatures, zero obfuscation findings, and zero suspicious IoC domains in the evidence. The extension has 1,315,269 users on Firefox, which could indicate either legitimate adoption or successful impersonation that has gained traction over time.
The strongest counterargument to this verdict is the absence of confirmed malicious behavior. No suspicious domains appear in the network findings, no malware signatures matched, and the code shows no obfuscation. A skeptic could argue this is simply a legitimate Dark Reader variant where developer attribution was not properly captured in the store metadata. However, the exact name match combined with missing developer information on a well-known extension is a documented typosquatting pattern. The legitimate Dark Reader has clear developer attribution, making this listing anomalous.
Recommendation: This requires verification of the publisher's identity. If this is not the legitimate Dark Reader, it should be flagged as impersonation regardless of whether malicious behavior has been detected, as the deception itself poses a risk to users who expect the trusted extension.
Key Reasons
- Exact name match to well-known legitimate extension Dark Reader
- Empty developer name field inconsistent with legitimate Dark Reader attribution
- High user count (1.3M) without developer verification
- No malware signatures or suspicious domains detected
False Positive Considerations
- Generic network findings without domain specificity
- Manifest permissions expected for dark mode functionality
Reviewed 2026-05-23; recommended action: escalate; model confidence 75%.
Firefox version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL