HIGH RISK NaN/100

Quick flomo - AI Reading Assistant & Citation Web Clipper

Unknown developer Ā· 10 users at risk

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

All Findings (205)

View all 205 security findings
Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: send.today

Indicator of Compromise

XIOC detected Domain: docs.bigmodel.cn

Indicator of Compromise

XIOC detected Domain: model.name

Indicator of Compromise

XIOC detected Email: exa***@gmail.com

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: www.w3.org

Indicator of Compromise

XIOC detected Domain: best.date

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: t.mx

Indicator of Compromise

XIOC detected Domain: p.fk

Indicator of Compromise

XIOC detected IP: ::af

Indicator of Compromise

XIOC detected IP: ::bef

Indicator of Compromise

XIOC detected IP: ::

Indicator of Compromise

XIOC detected URL: https://docs.bigmodel.cn/api-reference/

Indicator of Compromise

XIOC detected URL: https://shadow.wang/legal/quick-flomo/refund-policy.html

Indicator of Compromise

XIOC detected URL: https://placehold.co/200x200?text=Please+Add+Image';

Indicator of Compromise

XIOC detected URL: https://flomoapp.com/'))

Indicator of Compromise

XIOC detected URL: https://dutepjyocxcvecmsrtfp.supabase.co',

Indicator of Compromise

XIOC detected URL: https://accounts.google.com/o/oauth2/v2/auth?

Indicator of Compromise

XIOC detected URL: https://$

Indicator of Compromise

XIOC detected URL: https://quickflomo.com?ref=$

Indicator of Compromise

XIOC detected URL: https://*.supabase.co/*

Indicator of Compromise

XIOC detected URL: http://www.w3.org/2000/svg'

Indicator of Compromise

XIOC detected URL: https://shadow.wang/legal/quick-flomo/terms-of-service.html

Indicator of Compromise

XIOC detected URL: https://shadow.wang/legal/quick-flomo/privacy-policy.html

Indicator of Compromise

XIOC detected URL: https://flomoapp.com/iwh/xxx/xxx

Indicator of Compromise

XIOC detected URL: https://www.shadow.wang

Indicator of Compromise

XIOC detected URL: https://x.com/Gollumgulu

Indicator of Compromise

XIOC detected URL: https://docs.bigmodel.cn/cn/guide/models/free/glm-4.6v-flash

Indicator of Compromise

XIOC detected URL: https://docs.bigmodel.cn/cn/guide/models/text/glm-4.5#glm-4-5-air

Indicator of Compromise

XIOC detected URL: https://supabase.com/docs/reference/javascript

Indicator of Compromise

XIOC detected URL: https://clients2.google.com/service/update2/crx

Indicator of Compromise

XIOC detected URL: https://www.shadow.wang/

Indicator of Compromise

XIOC detected URL: https://flomoapp.com/*

Indicator of Compromise

XIOC detected Domain: tab.id

Indicator of Compromise

XIOC detected URL: https://docs.bigmodel.cn/cn/guide/models/text/glm-4.7

Indicator of Compromise

XIOC detected URL: https://docs.bigmodel.cn/cn/guide/models/vlm/glm-4.6v

Indicator of Compromise

XIOC detected Email: ab***@test.com

Indicator of Compromise

XIOC detected URL: http://www.w3.org/2000/svg

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: statusresult.data

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: result.todaystats.date

Indicator of Compromise

XIOC detected Domain: userstatus.email

Indicator of Compromise

XIOC detected Domain: userstatus.credits.total

Indicator of Compromise

XIOC detected Domain: aidailyusage.date

Indicator of Compromise

XIOC detected Domain: img.data

Indicator of Compromise

XIOC detected Domain: tagsarray.map

Indicator of Compromise

XIOC detected Domain: model.id

Indicator of Compromise

XIOC detected Domain: btn-subtle.pro

Indicator of Compromise

XIOC detected Domain: btn-user-avatar.show

Indicator of Compromise

XIOC detected Domain: subscription-badge.free

Indicator of Compromise

XIOC detected Domain: subscription-badge.pro

Indicator of Compromise

XIOC detected Domain: user-badge.free

Indicator of Compromise

XIOC detected Domain: user-badge.pro

Indicator of Compromise

XIOC detected Domain: attr.name

Indicator of Compromise

XIOC detected Domain: item.new

Indicator of Compromise

XIOC detected Domain: resumebtn.id

Indicator of Compromise

XIOC detected Domain: item.data

Indicator of Compromise

XIOC detected Domain: window.open

Indicator of Compromise

XIOC detected Domain: stats.total

Indicator of Compromise

XIOC detected Domain: invitations.map

Indicator of Compromise

XIOC detected Domain: item.email

Indicator of Compromise

XIOC detected Domain: user.id

Indicator of Compromise

XIOC detected Domain: user.email

Indicator of Compromise

XIOC detected Domain: user.is

Indicator of Compromise

XIOC detected Domain: user.credits.total

Indicator of Compromise

XIOC detected Domain: currentplaninfo.id

Indicator of Compromise

XIOC detected Domain: userstatus.is

Indicator of Compromise

XIOC detected URL: https://open.bigmodel.cn/*

Indicator of Compromise

XIOC detected Domain: loadingmsg.id

Indicator of Compromise

XIOC detected Domain: e.target

Indicator of Compromise

XIOC detected Domain: result.data

Indicator of Compromise

XIOC detected Domain: 946677852502-lom3ach1c2m8br0s42i18k0p3e42lgjo.apps.googleusercontent.com

Indicator of Compromise

XIOC detected Domain: chrome.runtime.id

Indicator of Compromise

XIOC detected Domain: hasharray.map

Indicator of Compromise

XIOC detected Domain: chromiumapp.org

Indicator of Compromise

XIOC detected Domain: window.location.search

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected URL: https://docs.bigmodel.cn/cn/guide/models/text/glm-4.5

Indicator of Compromise

XIOC detected Domain: statusresult.data.email

Indicator of Compromise

XIOC detected Domain: statusresult.data.is

Indicator of Compromise

XIOC detected Domain: currentuser.is

Indicator of Compromise

XIOC detected Domain: session.user.is

Indicator of Compromise

XIOC detected Domain: email.com

Indicator of Compromise

XIOC detected Domain: shadow.nexus

Indicator of Compromise

XIOC detected Domain: placehold.co

Indicator of Compromise

XIOC detected Domain: accounts.google.com

Indicator of Compromise

XIOC detected Domain: quickflomo.com

Indicator of Compromise

XIOC detected Domain: gmail.com

Indicator of Compromise

XIOC detected Domain: test.com

Indicator of Compromise

XIOC detected Domain: www.shadow.wang

Indicator of Compromise

XIOC detected Domain: flomoapp.com

Indicator of Compromise

XIOC detected Domain: open.bigmodel.cn

Indicator of Compromise

XIOC detected Domain: supabase.co

Indicator of Compromise

XIOC detected Domain: toast.show

Indicator of Compromise

XIOC detected Domain: shadow.wang

Indicator of Compromise

XIOC detected Domain: x.com

Indicator of Compromise

XIOC detected Domain: console.info

Indicator of Compromise

XIOC detected Domain: supabase.com

Indicator of Compromise

XIOC detected Domain: chrome.storage

Indicator of Compromise

XIOC detected Domain: data.ai

Indicator of Compromise

XIOC detected Domain: session.user.email

Indicator of Compromise

XIOC detected Domain: window.id

Indicator of Compromise

XIOC detected Domain: chrome.sidepanel.open

Indicator of Compromise

XIOC detected Domain: options.author

Indicator of Compromise

XIOC detected Domain: m.id

Indicator of Compromise

XIOC detected Domain: window.ai

Indicator of Compromise

XIOC detected Domain: window.free

Indicator of Compromise

XIOC detected Domain: window.pro

Indicator of Compromise

XIOC detected Domain: params.total

Indicator of Compromise

XIOC detected Domain: levels.info

Indicator of Compromise

XIOC detected Domain: sendbtn.id

Indicator of Compromise

XIOC detected Domain: appicon.id

Indicator of Compromise

XIOC detected Domain: btntext.id

Indicator of Compromise

XIOC detected Domain: element.id

Indicator of Compromise

XIOC detected Domain: c.date

Indicator of Compromise

XIOC detected IP: 2::

Indicator of Compromise

XIOC detected IP: 0::

Indicator of Compromise

XIOC detected IP: 1::

Indicator of Compromise

XIOC detected Domain: session.user.id

Indicator of Compromise

XIOC detected Domain: error.name

Indicator of Compromise

XIOC detected Domain: rect.top

Indicator of Compromise

XIOC detected Domain: host.style.top

Indicator of Compromise

XIOC detected Domain: popover.style.top

Indicator of Compromise

XIOC detected Domain: host.id

Indicator of Compromise

XIOC detected Domain: stats.date

Indicator of Compromise

XIOC detected Domain: metadata.author

Indicator of Compromise

XIOC detected Domain: schema.org

Indicator of Compromise

XIOC detected Domain: item.author

Indicator of Compromise

XIOC detected Domain: item.author.name

Indicator of Compromise

XIOC detected Domain: data.author

Indicator of Compromise

XIOC detected Domain: data.author.name

Indicator of Compromise

XIOC detected Domain: u.dj

Indicator of Compromise

XIOC detected Domain: w.bw

Indicator of Compromise

XIOC detected Domain: tl.np

Indicator of Compromise

XIOC detected Domain: c.do

Indicator of Compromise

XIOC detected Domain: date.now

Indicator of Compromise

XIOC detected Domain: clients2.google.com

Indicator of Compromise

XIOC detected Domain: dutepjyocxcvecmsrtfp.supabase.co

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_crypto_operations

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_file_manipulation

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_persistence_mechanism

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_file_manipulation

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_crypto_operations

Code Quality Issue

YARA rule match: -postinstall_persistence_mechanism

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_file_manipulation

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_file_download

Code Quality Issue

YARA rule match: -postinstall_system_command

Code Quality Issue

YARA rule match: -postinstall_persistence_mechanism

Code Quality Issue

YARA rule match: -postinstall_network_communication

Code Quality Issue

YARA rule match: -postinstall_obfuscation

Code Quality Issue

YARA rule match: -postinstall_file_manipulation

Code Quality Issue

YARA rule match: -postinstall_file_manipulation

Code Quality Issue

YARA rule match: -postinstall_obfuscation

Code Quality Issue

YARA rule match: -LocalStorageShouldNotBeUsed

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/9/2026 Ā· Version 1.4.0

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.