Is Bitcleaner Surfguard safe?

High risk

Bitcleaner Surfguard is high risk. On every new site, Bitcleaner Surfguard POSTs the exact URL, tab ID, and a persistent tracking ID to bitcleaner-surfguard.com in the background, no prompt shown. Confirmed by capturing live network traffic during normal browsing.…

Andre.K.v1.0.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Full Browsing URL Sent to Remote Server on Every Navigation

On every new site, Bitcleaner Surfguard POSTs the exact URL, tab ID, and a persistent tracking ID to bitcleaner-surfguard.com in the background, no prompt shown.

Confirmed by capturing live network traffic during normal browsing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any website.

The extension did this

Bitcleaner Surfguard immediately POSTs the full URL you visited to its own server.

This happens in the background on every domain change, before any page content loads. No user interaction required.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://bitcleaner-surfguard.com/roh?sovish=mb7m2xd8d8an
JSON response containing displayScore (green/orange/red) used to update the extension icon
Headers
Content-typeapplication/x-www-form-urlencoded
Body
version=1.0.0&tabId=1077145710&title=google.com&domain=google.com&url=https%3A%2F%2Fwww.google.com%2F&sovish=mb7m2xd8d8an&action=getScore&active=true&name=bitcleaner_surfguard
03EvidenceFIELD TABLE
What Bitcleaner Surfguard sends on every page visit:
FieldValueWhy it matters
The URL you are visiting
https://www.amazon.com/dp/B09G3HRMVBThe exact full URL of the page you navigated to, including any path and query parameters.
Domain of the page
amazon.comThe root domain extracted from your URL, used to track which sites you visit.
Browser tab ID
1077145710The internal ID of the tab you are browsing in. Combined with the tracking ID, this links requests to a specific browser session.
Your tracking ID
mb7m2xd8d8anA persistent identifier assigned to your browser on first install. Every request you make from this device carries this ID, forever.
Extension name
bitcleaner_surfguardSent as a hardcoded identifier so the server knows which extension product is reporting.
04EvidenceCODE COMPARE
The code that does this

The code that fires on every navigation, from the shipping bg.js:

What it actually does
The navigation listener
// Fires every time a tab starts loading any URL
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
  if (changeInfo.status === 'loading') {
    sendNavigationReport(tab); // triggers the data exfiltration
  }
});
The payload assembler
// Builds the POST body sent to bitcleaner-surfguard.com/roh
function buildPayload(tab) {
  var domain = extractRootDomain(tab.url); // e.g. 'amazon.com'
  return {
    version: '1.0.0',
    tabId: tab.id,            // internal browser tab ID
    title: tab.title,         // page title (domain-only in practice)
    domain: domain,           // root domain of visited page
    url: tab.url,             // FULL URL including path and query string
    sovish: userTrackingId,   // persistent user ID from chrome.storage.local
    action: 'getScore',
    active: tab.active,
    name: 'bitcleaner_surfguard'
  };
}
05EvidenceTHIRD PARTY LIST
Where your browsing data ends up:
  • bitcleaner-surfguard.com

    Primary server. Receives every navigation event: full URL, domain, tab ID, persistent tracking ID. Also serves /dih, the registration endpoint assigning the ID.

06EvidenceARTIFACT
Reproduce it yourself

Run this in Chrome DevTools (Network tab works too, but this script intercepts at the fetch level) while Bitcleaner Surfguard is active. It hooks fetch() in the background service worker context and logs every outbound request to bitcleaner-surfguard.com, showing the full URL and decoded POST body.

RequiresChrome with Developer mode enabled
bitcleaner-nav-monitor.js · js
// bitcleaner-nav-monitor.js
// Paste this into the DevTools console of the Bitcleaner Surfguard service worker
// (chrome://extensions → Developer mode → click the service worker link for the extension)

(function() {
  const origFetch = globalThis.fetch.bind(globalThis);
  globalThis.fetch = async function(input, init) {
    const url = (input instanceof Request) ? input.url : String(input);
    if (url.includes('bitcleaner-surfguard.com')) {
      console.group('[BITCLEANER] Outbound request intercepted');
      console.log('URL:', url);
      if (init && init.body) {
        try {
          const decoded = decodeURIComponent(init.body.replace(/&/g, '\n'));
          console.log('POST body (decoded):\n' + decoded);
        } catch (e) {
          console.log('POST body (raw):', init.body);
        }
      }
      console.groupEnd();
    }
    return origFetch(input, init);
  };
  console.log('[BITCLEANER MONITOR] Installed. Navigate to any HTTP/HTTPS page to see captured requests.');
})();
How to run it
  1. 1
    Install Bitcleaner Surfguard.
  2. 2
    Enable Developer mode at chrome://extensions.
  3. 3
    Click 'service worker' to open DevTools.
  4. 4
    Paste this script, Enter.
  5. 5
    Navigate to any site.
  6. 6
    Watch for [BITCLEANER] entries with URL/POST body.
SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Permanent Tracking ID Assigned on Install, Sent with Every Request

On first install, Bitcleaner Surfguard contacts bitcleaner-surfguard.com, no prompt, and gets a tracking ID saved permanently.

That ID rides every future request, including URLs reported, linking your activity to one profile indefinitely.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install Bitcleaner Surfguard.

The extension did this

The extension immediately registers with bitcleaner-surfguard.com to get a unique ID for your browser, then saves it permanently.

From this point on, every browsing report the extension sends includes this ID, enabling the server to build a complete history of your web activity tied to a single persistent identifier.

02EvidenceSTORAGE DUMP
What's stored on your device

Your permanent tracking ID, stored locally and read on every service-worker startup. It never changes once set.

Locationchrome.storage.local key 'bubble'
Contents (JSON)
{
  "bubble": "mb7m2xd8d8an"
}
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://bitcleaner-surfguard.com/dih?sovish=bitcleaner_surfguard&version=1.0.0
Server returns the unique tracking ID string (e.g. 'mb7m2xd8d8an') that will be permanently assigned to this browser install
04EvidenceCODE COMPARE
The code that does this

How the tracking ID is assigned and attached to all future requests:

What it actually does
Startup: load or register tracking ID
var persistentUserId = '';    // the tracking ID (called 'sovish' on the wire)
var registrationUrl = 'https://bitcleaner-surfguard.com/dih?sovish=bitcleaner_surfguard&version=1.0.0';
var reportingUrl = 'https://bitcleaner-surfguard.com/roh';   // appended with ?sovish=<id>

initOnStartup();

function initOnStartup() {
  chrome.storage.local.get('bubble', function(stored) {
    if (stored.bubble) {
      // Already registered: load saved ID and attach to all future requests
      persistentUserId = stored.bubble;
      reportingUrl += '?sovish=' + persistentUserId;
    } else {
      // First install: request a new ID from the server
      registerWithServer();
    }
  });
}
Server registration and ID storage
function saveAssignedId(serverResponse) {
  if (serverResponse) {
    persistentUserId = serverResponse;          // store in memory
    reportingUrl += '?sovish=' + persistentUserId; // tag the reporting endpoint
    chrome.storage.local.set({ bubble: persistentUserId }); // persist forever
  }
}
function registerWithServer() {
  httpGet(registrationUrl, saveAssignedId); // GET /dih, callback saves response
}
05EvidencePLAIN NOTE
This ID persists even if you clear cookies or browsing history

The tracking ID is stored in `chrome.storage.local`, which is separate from your browser's cookies and browsing history. Clearing cookies, browsing history, or even cache does **not** remove it. The only way to reset the ID is to uninstall and reinstall the extension — or to manually clear extension storage via the browser's developer tools.

What it can do

Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026aeefnonlfngaeblgiipagcfmcakbmmjk