Is Billfish - Free material management tool safe?

Medium risk

Billfish is medium risk. Billfish's popup and in-page prompts send events via the bundled SensorsData SDK to sa.aunload.com. A captured BTriggerWindow POST held browser/version data, screen details, a prompt name, and page context. hm.baidu.com is also allowed.

billfishchinav4.0.5Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Behavior events reach external analytics endpoints

Billfish's popup and in-page prompts send events via the bundled SensorsData SDK to sa.aunload.com.

A captured BTriggerWindow POST held browser/version data, screen details, a prompt name, and page context. hm.baidu.com is also allowed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open Billfish or trigger one of its in-page collection prompts.

The popup and content script create named behavior events when these UI paths run.

The extension did this

The extension forwards the event name and page-context fields to an external analytics collector.

Dynamic analysis captured the resulting SensorsData request to `sa.aunload.com`.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://sa.aunload.com:4006/sa.gif?project=production
Observed during dynamic analysis: the decoded body was a SensorsData track event named `BTriggerWindow` with browser/version, screen/viewport, `pc_Tip_name`, and `chrome-extension://piohkopmiebhgodfkcfcmjbmgkcnjnmf/background.js` context.
03EvidenceFIELD TABLE
Decoded fields observed in the analytics event
FieldValueWhy it matters
Event name
BTriggerWindowShows which extension behavior was recorded about your interaction.
Prompt or interaction name
pc_Tip_name: PopupDialogIdentifies the specific Billfish prompt or collection action shown while you browse.
Browser details
Chrome 126.0.6478.127 (illustrative value; field observed)Adds device context that can help separate your browser from other users' browsers.
Screen and viewport
1920x1080 screen, 1280x720 viewport (illustrative value; field observed)Adds display-size context to the behavior event sent about your session.
Extension page context
chrome-extension://piohkopmiebhgodfkcfcmjbmgkcnjnmf/background.jsTies the event to the Billfish extension context instead of a normal website page.
04EvidenceCODE COMPARE
The code that does this

How the event is created, handed to the background script, and sent

What it actually does
Popup event creationassets/popup.js
async sendToSa(e, t) {
  this.backCaller.call(j.SendToSa, {
    id: e,
    sendData: t
  })
}
return async function() {
  const e = {
    pc_Tip_name: L.PopupDialog
  };
  ge.sendToSa("BTriggerWindow", e);
  const t = await he.getConfig({
    appId: z,
    appVersion: "4.0.5"
  });
  g.value = t[0], g.value.version > "4.0.5" && (o.value = !0)
}()
Content-script prompt eventcontent.js
openBillfishDom() {
  try {
    this.backCaller.call(Z.SendToSa, {
      id: "BTriggerWindow",
      sendData: {
        pc_Tip_name: R.OpenBillfish
      }
    });
    return '\n        <div class="billfish-no-detect-bac" id="billfishNoDeetctBac" style="z-index: 99999999999999">\n          <div class="billfish-all-tips">\n            <div id="open-billfish" class="tips-open-buttom">打开Billfish</div>\n          </div>\n        </div>\n      '
  } catch (e) {
    console.log(e)
  }
}
Background analytics setup and send handlerbackground.js
Object.assign(fe.para_default, {
  send_type: "beacon"
}), fe.init({
  send_type: "beacon",
  server_url: "https://sa.aunload.com:4006/sa?project=production",
  use_app_track: !0,
  show_log: false,
  heatmap: {
    clickmap: "not_collect",
    scroll_notice_map: "not_collect"
  }
});
this.invoker.bind(Br.SendToSa, (async e => {
  we.setSensors(e.input.id, e.input.sendData)
}));
sendData: function(e, t) {
  var r = se(e.properties);
  !0 === Wt.para.debug_mode ? (Wt.log(e), Wt.saEvent.debugPath(JSON.stringify(e), t)) : Wt.sendState.getSendCall(e, r, t)
},
encodeTrackData: function(e) {
  var t = E(e),
    r = "crc=" + C(t);
  return "data=" + encodeURIComponent(t) + "&ext=" + encodeURIComponent(r)
}
Lr.sendCall = function(e, t, r) {
  var n = {
    server_url: t,
    data: JSON.stringify(e.data),
    callback: r,
    config: e.config
  };
  h(Wt.para.jsapp) && !Wt.para.jsapp.isOnline && "function" == typeof Wt.para.jsapp.setData ? (delete n.callback, n = JSON.stringify(n), Wt.para.jsapp.setData(n)) : this.realtimeSend(n)
}
05EvidenceTHIRD PARTY LIST
External analytics-related hosts in this claim
  • sa.aunload.com

    SensorsData collector that received the observed `BTriggerWindow` event over HTTPS.

  • hm.baidu.com

    Baidu Analytics host embedded in the background script's external endpoint list.

What it can do

Permissions this extension asks for, as declared in version 4.0.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Act on the current tab, but only after you click the extension

    activeTab

  • Watch every request your browser makes

    webRequest

  • Run its own code inside the pages you visit

    scripting

  • Add items to the right-click menu

    contextMenus

Updated 30 September 2026piohkopmiebhgodfkcfcmjbmgkcnjnmf