Pinterest Image Downloader | Futoo
The AI review rates the findings as likely false positive, but the risk score (58/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v1.2.4
- Artifact
- SHA256 F31…70E
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
10 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 4 | background.jschunks/popup-Jc4LYkE7.js_metadata/verified_contents.json +1 more | - |
| LOW | OriginsNotVerified | 1 | content-scripts/content.js | - |
| LOW | postinstall file manipulation | 4 | background.jscontent-scripts/content.jschunks/settings-DNk9vnNa.js +1 more | - |
| LOW | postinstall system command | 7 | content-scripts/content.jscontent-scripts/pageScript.jsbackground.js +4 more | - |
| LOW | postinstall environment access | 2 | chunks/options-CEhi9dP9.jschunks/popup-Jc4LYkE7.js | - |
| LOW | postinstall obfuscation | 3 | content-scripts/content.jschunks/settings-DNk9vnNa.jschunks/popup-Jc4LYkE7.js | - |
| LOW | postinstall network communication | 4 | content-scripts/pageScript.jscontent-scripts/content.jschunks/settings-DNk9vnNa.js +1 more | - |
| LOW | postinstall file download | 20 | content-scripts/pageScript.js_locales/de/messages.json_locales/ja/messages.json +17 more | - |
| LOW | NoUseWeakRandom | 2 | content-scripts/content.jschunks/settings-DNk9vnNa.js | - |
| LOW | postinstall persistence mechanism | 3 | content-scripts/pageScript.jsbackground.jscontent-scripts/content.js | - |
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
10 rules(50 hits)Requested Permissions
34 permissionsManage, modify, and monitor downloads
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This Pinterest image downloader extension shows no evidence of malicious behavior. The 57 IoC findings flagged by the analysis are not suspicious network activity—they are false positives from the XIOC extractor misreading JavaScript property access chains as domains. For example, e.prototype.open and c.videos.video are clearly object property chains, not actual domain names. The legitimate Pinterest domains detected (pinterest.com, pinterest.ca, pinterest.fr, pinterest.de, pinterest.jp, pinterest.co.uk) are expected behavior for an extension that downloads content from Pinterest; the extension must interact with these domains to function.
The network finding NET-FETCH-chunks/pin-CHxpJTPM.js-1 represents a standard fetch call in a webpack chunked JavaScript file, which is normal for modern browser extensions. There are zero malware signatures, zero obfuscation findings, and zero code-smell findings. The absence of these critical threat indicators is a strong signal that this extension is benign.
The developer uses a generic Gmail address ([email protected]) rather than a verified publisher account, which is a minor concern. However, anonymous developers are common for utility extensions, and this alone does not indicate malicious intent. The extension's functionality matches its stated purpose: downloading images and videos from Pinterest. There is no evidence of credential theft, browser hijacking, data exfiltration to unknown domains, or proxyware behavior.
The strongest counterargument to this verdict would be the high finding count (60 total) combined with an anonymous publisher. However, finding count is not evidence of threat—finding nature is. All 57 IoC findings are either legitimate Pinterest infrastructure or XIOC false positives from property chains. The two network findings are standard fetch calls in bundled code. Without malware signatures, obfuscation, or suspicious external domains, the high finding count is noise, not signal. A skeptic might argue that 6,000 users could be compromised, but user count does not correlate with maliciousness, and the code itself shows no harmful behavior.
Key Reasons
- Zero malware signatures detected
- Zero obfuscation findings
- IoCs are legitimate Pinterest domains or property chain false positives
- Network findings are standard fetch calls in bundled code
- Extension functionality matches stated purpose
False Positive Considerations
- XIOC property access chains misread as domains
- Legitimate Pinterest domains flagged as suspicious
- Webpack chunked JavaScript triggering network findings
Reviewed 2026-06-01; recommended action: suppress false positive; model confidence 85%.
Chrome version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
XB, block all ads
[email protected]
Zent Translate
[email protected]
Google Translate in Side Panel
[email protected]
YT Subtitle - Video Summarizer & Translator
[email protected]
gTab
[email protected]
ChatGPT Sidebar
[email protected]