Post Translator for TWITTER X.COM
Confirmed member of a tracked malicious supply-chain campaign.
Analysis record
- Analysed
- 7 months ago
- Version
- v1.2.7
- Artifact
- SHA256 DF4…6D5
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 2 | js/jquery.js_metadata/verified_contents.json | Risky Plugins Authors FP 30% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 1 | js/jquery.js | FP 5% |
| HIGH | postinstall system command System command execution detected | 3 | js/jquery.jsjs/cmain.jsfont/Nunito/Nunito-Bold.ttf | Risky Plugins Authors FP 10% |
| HIGH | postinstall network communication Network communication detected | 1 | js/jquery.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 3 | popup/main.jsjs/jquery.jsjs/cmain.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 16 | font/Nunito/Nunito-Light.ttffont/Nunito/Nunito-Medium.ttffont/Nunito/Nunito-ExtraLight.ttf +13 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 1 | js/jquery.js | Risky Plugins Authors FP 20% |
| HIGH | SQLInjection SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 2 | js/jquery.jspopup/main.js | FP 10% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
11 evidence rows available.
Finding Categories
YARA Rules Matched
8 rules(29 hits)Requested Permissions
1 permissionAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-24. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality strong.
The Post Translator for TWITTER X.COM extension presents a classic false-positive scenario. While automated scanning generated 30 findings with 29 marked high severity, the nature of these findings reveals they stem from well-documented false-positive patterns rather than actual malicious behavior.
All malware-signature findings originate from YARA rules in the postinstall_* family, which are known to fire on basic JavaScript patterns. For example, YARA--postinstall_persistence_mechanism triggered in font files like /font/Nunito/Nunito-Light.ttf and /font/Nunito/Nunito-Bold.ttf. Binary font files cannot contain executable persistence mechanisms—this is a scanner artifact. Similarly, YARA--SQLInjection matched in /popup/main.js and /js/jquery.js, but SQL injection rules are code-quality checks that trigger on any JavaScript referencing database-like patterns, not actual vulnerabilities.
The code-smell findings include YARA--postinstall_file_manipulation in /popup/main.js and YARA--postinstall_obfuscation in /js/jquery.js. These are bundled dependencies (jQuery is a standard npm package) that trigger their own YARA matches, creating multiplicative false positives. The single network finding shows a jQuery AJAX call in js/cmain.js:123, which is expected behavior for a translation extension that needs to fetch and process tweet content.
The strongest counterargument would be the high severity count (29 high, 1 medium). However, severity ratings in automated scanners don't reflect actual risk when the underlying rules are known false positives. The postinstall_* rules are explicitly documented as matching basic Node.js patterns that appear in legitimate code. The SQLInjection rule is a code-quality check, not a malware detector. The fact that these rules fired in font files (.ttf) proves they're not detecting actual malicious behavior—binary files cannot contain JavaScript-based persistence mechanisms.
The extension's purpose (translating tweets) aligns with its behavior (AJAX calls for content fetching). There are no suspicious domains, no obfuscation findings, no credential theft indicators, and no browser hijacking behavior. The developer uses an email address rather than a company name, which is common for small extensions but doesn't indicate malicious intent. This extension should be classified as benign with the findings suppressed as false positives.
Key Reasons
- All malware-signature findings are from documented postinstall_* false-positive rules
- YARA matches in binary .ttf files prove scanner artifacts, not real threats
- SQLInjection rule is a code-quality check, not malware detection
- Single network finding is normal jQuery AJAX for translation functionality
- No suspicious domains, obfuscation, or credential theft indicators
False Positive Considerations
- postinstall_* YARA rules matching basic JS patterns
- SQLInjection code-quality rule in bundled jQuery
- YARA matches in binary .ttf font files
- Bundled dependency (jquery.js) triggering multiplicative findings
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Бесплатный ВПН для Ютуб без ограничений в России
[email protected]
Discord VPN | Расширение для браузера – надежный доступ к Discord
[email protected]
VPNtube - Ютуб без замедления
[email protected]
VPN для ChatGPT
[email protected]
РуТрекер VPN - расширение для доступа к сайту
[email protected]
VPN для LinkedIn
[email protected]