Chrome Web Store

Post Translator for TWITTER X.COM

by [email protected] · 4.0K users · 4.7 rating
ec082941-fcac-5e9d-b6ff-1f43037f4a2e | v1.2.7
50/ 100
MEDIUM risk
Threat verdict
Do not install

Confirmed member of a tracked malicious supply-chain campaign.

Analysis record

Analysed
7 months ago
Version
v1.2.7
Artifact
SHA256 DF4…6D5
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

30 detail rows

YARA Rule Matches

8 rules
SeverityRuleHitsFilesMetadata
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

1
js/jquery.js
FP 5%
HIGHpostinstall system command

System command execution detected

3
font/Nunito/Nunito-Bold.ttfjs/jquery.jsjs/cmain.js
Risky Plugins Authors FP 10%
HIGHpostinstall network communication

Network communication detected

1
js/jquery.js
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

3
js/cmain.jspopup/main.jsjs/jquery.js
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

16
font/Nunito/Nunito-Regular.ttffont/Nunito/Nunito-LightItalic.ttffont/Nunito/Nunito-Bold.ttf +13 more
Risky Plugins Authors FP 20%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

1
js/jquery.js
Risky Plugins Authors FP 20%
HIGHSQLInjection

SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

2
popup/main.jsjs/jquery.js
FP 10%
HIGHpostinstall crypto operations

Cryptographic operations detected

2
js/jquery.js_metadata/verified_contents.json
Risky Plugins Authors FP 30%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

155 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

43
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
22
Portfolio

11 evidence rows available.

Finding Categories

29
Malware Signatures
1
Network
155
IoC Indicators

YARA Rules Matched

8 rules(29 hits)
NoUseWeakRandom postinstall system command postinstall network communication postinstall file manipulation postinstall persistence mechanism postinstall obfuscation SQLInjection postinstall crypto operations

Requested Permissions

1 permission
storage
Low

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-24. The review verdict is likely false positive with 85% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality strong.

The Post Translator for TWITTER X.COM extension presents a classic false-positive scenario. While automated scanning generated 30 findings with 29 marked high severity, the nature of these findings reveals they stem from well-documented false-positive patterns rather than actual malicious behavior.

All malware-signature findings originate from YARA rules in the postinstall_* family, which are known to fire on basic JavaScript patterns. For example, YARA--postinstall_persistence_mechanism triggered in font files like /font/Nunito/Nunito-Light.ttf and /font/Nunito/Nunito-Bold.ttf. Binary font files cannot contain executable persistence mechanisms—this is a scanner artifact. Similarly, YARA--SQLInjection matched in /popup/main.js and /js/jquery.js, but SQL injection rules are code-quality checks that trigger on any JavaScript referencing database-like patterns, not actual vulnerabilities.

The code-smell findings include YARA--postinstall_file_manipulation in /popup/main.js and YARA--postinstall_obfuscation in /js/jquery.js. These are bundled dependencies (jQuery is a standard npm package) that trigger their own YARA matches, creating multiplicative false positives. The single network finding shows a jQuery AJAX call in js/cmain.js:123, which is expected behavior for a translation extension that needs to fetch and process tweet content.

The strongest counterargument would be the high severity count (29 high, 1 medium). However, severity ratings in automated scanners don't reflect actual risk when the underlying rules are known false positives. The postinstall_* rules are explicitly documented as matching basic Node.js patterns that appear in legitimate code. The SQLInjection rule is a code-quality check, not a malware detector. The fact that these rules fired in font files (.ttf) proves they're not detecting actual malicious behavior—binary files cannot contain JavaScript-based persistence mechanisms.

The extension's purpose (translating tweets) aligns with its behavior (AJAX calls for content fetching). There are no suspicious domains, no obfuscation findings, no credential theft indicators, and no browser hijacking behavior. The developer uses an email address rather than a company name, which is common for small extensions but doesn't indicate malicious intent. This extension should be classified as benign with the findings suppressed as false positives.

Key Reasons

  • All malware-signature findings are from documented postinstall_* false-positive rules
  • YARA matches in binary .ttf files prove scanner artifacts, not real threats
  • SQLInjection rule is a code-quality check, not malware detection
  • Single network finding is normal jQuery AJAX for translation functionality
  • No suspicious domains, obfuscation, or credential theft indicators

False Positive Considerations

  • postinstall_* YARA rules matching basic JS patterns
  • SQLInjection code-quality rule in bundled jQuery
  • YARA matches in binary .ttf font files
  • Bundled dependency (jquery.js) triggering multiplicative findings

About This Extension

The "Tweet Translator for X (Twitter)" extension is a convenient tool for anyone who wants to easily and quickly translate tweets, comments, and other text on the X (formerly Twitter) platform. No matter what language a post is written in, this extension allows you to instantly translate it into your preferred language, making content accessible and easy to understand. 💢 Key Features: Instant Translation: Translate tweets, comments, and profile descriptions with a single click. Support for Multiple Languages: The extension supports over 100 languages, including Russian, English, Spanish, Chinese, Arabic, and many more. Automatic Language Detection: The extension automatically recognizes the original language and translates the text into your chosen language. User-Friendly Interface: Translations appear directly below the original text without disrupting the page layout. Customizable Translation Language: You can select your preferred target language in the extension's settings. 💢 Who is this extension for: For users who want to read tweets in foreign languages. For those who follow international news, bloggers, and celebrities. For researchers and analysts studying content from different countries. For everyone who wants to broaden their horizons and understand more. 🔥 Download the "Tweet Translator for X (Twitter)" now and make your social media experience even more comfortable and informative! 🌐✨

Frequently Asked Questions