Is Bitcleaner Surfguard safe?
Bitcleaner Surfguard is high risk. On every new site, Bitcleaner Surfguard POSTs the exact URL, tab ID, and a persistent tracking ID to bitcleaner-surfguard.com in the background, no prompt shown. Confirmed by capturing live network traffic during normal browsing.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Full Browsing URL Sent to Remote Server on Every Navigation
On every new site, Bitcleaner Surfguard POSTs the exact URL, tab ID, and a persistent tracking ID to bitcleaner-surfguard.com in the background, no prompt shown.
Confirmed by capturing live network traffic during normal browsing.
You navigate to any website.
Bitcleaner Surfguard immediately POSTs the full URL you visited to its own server.
This happens in the background on every domain change, before any page content loads. No user interaction required.
| Content-type | application/x-www-form-urlencoded |
version=1.0.0&tabId=1077145710&title=google.com&domain=google.com&url=https%3A%2F%2Fwww.google.com%2F&sovish=mb7m2xd8d8an&action=getScore&active=true&name=bitcleaner_surfguard
| Field | Value | Why it matters | |
|---|---|---|---|
The URL you are visiting | https://www.amazon.com/dp/B09G3HRMVB | The exact full URL of the page you navigated to, including any path and query parameters. | |
Domain of the page | amazon.com | The root domain extracted from your URL, used to track which sites you visit. | |
Browser tab ID | 1077145710 | The internal ID of the tab you are browsing in. Combined with the tracking ID, this links requests to a specific browser session. | |
Your tracking ID | mb7m2xd8d8an | A persistent identifier assigned to your browser on first install. Every request you make from this device carries this ID, forever. | |
Extension name | bitcleaner_surfguard | Sent as a hardcoded identifier so the server knows which extension product is reporting. |
The code that fires on every navigation, from the shipping bg.js:
// Fires every time a tab starts loading any URL
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
if (changeInfo.status === 'loading') {
sendNavigationReport(tab); // triggers the data exfiltration
}
});// Builds the POST body sent to bitcleaner-surfguard.com/roh
function buildPayload(tab) {
var domain = extractRootDomain(tab.url); // e.g. 'amazon.com'
return {
version: '1.0.0',
tabId: tab.id, // internal browser tab ID
title: tab.title, // page title (domain-only in practice)
domain: domain, // root domain of visited page
url: tab.url, // FULL URL including path and query string
sovish: userTrackingId, // persistent user ID from chrome.storage.local
action: 'getScore',
active: tab.active,
name: 'bitcleaner_surfguard'
};
}- bitcleaner-surfguard.com
Primary server. Receives every navigation event: full URL, domain, tab ID, persistent tracking ID. Also serves /dih, the registration endpoint assigning the ID.
Run this in Chrome DevTools (Network tab works too, but this script intercepts at the fetch level) while Bitcleaner Surfguard is active. It hooks fetch() in the background service worker context and logs every outbound request to bitcleaner-surfguard.com, showing the full URL and decoded POST body.
// bitcleaner-nav-monitor.js
// Paste this into the DevTools console of the Bitcleaner Surfguard service worker
// (chrome://extensions → Developer mode → click the service worker link for the extension)
(function() {
const origFetch = globalThis.fetch.bind(globalThis);
globalThis.fetch = async function(input, init) {
const url = (input instanceof Request) ? input.url : String(input);
if (url.includes('bitcleaner-surfguard.com')) {
console.group('[BITCLEANER] Outbound request intercepted');
console.log('URL:', url);
if (init && init.body) {
try {
const decoded = decodeURIComponent(init.body.replace(/&/g, '\n'));
console.log('POST body (decoded):\n' + decoded);
} catch (e) {
console.log('POST body (raw):', init.body);
}
}
console.groupEnd();
}
return origFetch(input, init);
};
console.log('[BITCLEANER MONITOR] Installed. Navigate to any HTTP/HTTPS page to see captured requests.');
})();
- 1Install Bitcleaner Surfguard.
- 2Enable Developer mode at chrome://extensions.
- 3Click 'service worker' to open DevTools.
- 4Paste this script, Enter.
- 5Navigate to any site.
- 6Watch for [BITCLEANER] entries with URL/POST body.
Permanent Tracking ID Assigned on Install, Sent with Every Request
On first install, Bitcleaner Surfguard contacts bitcleaner-surfguard.com, no prompt, and gets a tracking ID saved permanently.
That ID rides every future request, including URLs reported, linking your activity to one profile indefinitely.
You install Bitcleaner Surfguard.
The extension immediately registers with bitcleaner-surfguard.com to get a unique ID for your browser, then saves it permanently.
From this point on, every browsing report the extension sends includes this ID, enabling the server to build a complete history of your web activity tied to a single persistent identifier.
Your permanent tracking ID, stored locally and read on every service-worker startup. It never changes once set.
chrome.storage.local key 'bubble'{
"bubble": "mb7m2xd8d8an"
}How the tracking ID is assigned and attached to all future requests:
var persistentUserId = ''; // the tracking ID (called 'sovish' on the wire)
var registrationUrl = 'https://bitcleaner-surfguard.com/dih?sovish=bitcleaner_surfguard&version=1.0.0';
var reportingUrl = 'https://bitcleaner-surfguard.com/roh'; // appended with ?sovish=<id>
initOnStartup();
function initOnStartup() {
chrome.storage.local.get('bubble', function(stored) {
if (stored.bubble) {
// Already registered: load saved ID and attach to all future requests
persistentUserId = stored.bubble;
reportingUrl += '?sovish=' + persistentUserId;
} else {
// First install: request a new ID from the server
registerWithServer();
}
});
}function saveAssignedId(serverResponse) {
if (serverResponse) {
persistentUserId = serverResponse; // store in memory
reportingUrl += '?sovish=' + persistentUserId; // tag the reporting endpoint
chrome.storage.local.set({ bubble: persistentUserId }); // persist forever
}
}
function registerWithServer() {
httpGet(registrationUrl, saveAssignedId); // GET /dih, callback saves response
}The tracking ID is stored in `chrome.storage.local`, which is separate from your browser's cookies and browsing history. Clearing cookies, browsing history, or even cache does **not** remove it. The only way to reset the ID is to uninstall and reinstall the extension — or to manually clear extension storage via the browser's developer tools.
What it can do
Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Run its own code inside the pages you visit
scripting