Is CFCA CryptoKit.ADBC Extension safe?

Low risk

CFCA CryptoKit.ADBC bridges pages on adbc.com.cn and hellotech.top to a locally installed bank PKI/certificate app via native messaging.

The extension's only job is to relay messages between web pages and a locally installed CFCA native host that performs certificate and signing operations for online banking. Its background script forwards a page-supplied host name into chrome.runtime.connectNative and passes message payloads through verbatim, with the only control being that the calling page must be served from *.adbc.com.cn or *.hellotech.top. Because those allowed origins include plain http:// as well as https://, a page on those domains reached over an untrusted network could also open the native bridge. The extension itself sends no data to any remote server.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

liangjiangjianv3.4.0.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

Local CFCA native messaging host (installed PKI/signing application)
Updated 17 September 2026klnnalhfongaiigdellejemjcbialgln