BugKit Visual Bug Reporting
Score-based assessment (medium risk, 61/100). Last analyst review covers version 1.1.0.
Analysis record
- Analysed
- 4 weeks ago
- Version
- v1.2.1
- Artifact
- SHA256 979…752
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 3 | chunks/options-BUHiIuCZ.jsbackground.jscontent-scripts/content.js | - |
| LOW | postinstall persistence mechanism | 2 | background.jscontent-scripts/content.js | - |
| LOW | postinstall file download | 8 | rrweb.jschunks/options-BUHiIuCZ.jspage-instrumentation.js +5 more | - |
| LOW | NoUseWeakRandom | 4 | page-instrumentation.jschunks/index-BHgQiXBV.jsbackground.js +1 more | - |
| LOW | postinstall obfuscation | 6 | content-scripts/content.jsrrweb.jschunks/options-BUHiIuCZ.js +3 more | - |
| LOW | postinstall crypto operations | 4 | chunks/options-BUHiIuCZ.jsbackground.jschunks/index-BHgQiXBV.js +1 more | - |
| LOW | postinstall file manipulation | 9 | chunks/offscreen-NiXevi8N.jsassets/options-JevPvTQw.cssrrweb.js +6 more | - |
| LOW | postinstall system command | 11 | _locales/en/messages.jsonindex.htmlassets/options-JevPvTQw.css +8 more | - |
| LOW | postinstall environment access | 3 | chunks/index-BHgQiXBV.jschunks/popup-DX85XD3G.jschunks/options-BUHiIuCZ.js | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | background.js | - |
| LOW | postinstall network communication | 8 | chunks/offscreen-NiXevi8N.jsrrweb.jschunks/options-BUHiIuCZ.js +5 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | manifest.json | - |
| LOW | credential metamask extension | 1 | chunks/options-BUHiIuCZ.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceDracon
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
13 rules(61 hits)Requested Permissions
9 permissionsFull access to Chrome DevTools debugging protocol
Access and modify data on every website you visit
Read and modify cookies on all sites
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The BugKit Visual Bug Reporting extension has a high number of IoC findings, but upon closer inspection, these findings appear to be related to the extension's functionality of auto-capturing screen, console logs, and network requests for faster debugging. The IoC findings are primarily related to XIOC detected domains, such as remoteid.map, doctype.name, and d.documentelement.style, which do not seem to be malicious. The extension's description and functionality suggest that it is a legitimate tool for bug reporting and debugging. However, the lack of developer information and the high number of IoC findings may raise some concerns. A counterargument to this verdict could be that the extension's ability to capture network requests and console logs could potentially be used for malicious purposes, such as data exfiltration. However, there is no evidence to suggest that this is the case, and the extension's functionality appears to be focused on legitimate debugging and bug reporting purposes. Therefore, based on the evidence, it is likely that this extension is a false positive.
Key Reasons
- High number of IoC findings related to XIOC detected domains
- Lack of developer information
- Extension's functionality appears to be focused on legitimate debugging and bug reporting purposes
False Positive Considerations
- IoC extractor garbage
- XIOC detected domains
Reviewed 2026-05-31; recommended action: suppress false positive; model confidence 80%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace