Is CFCA CryptoKit.Paperless.SINOTRANS Extension safe?

Low risk

CFCA CryptoKit connects to any native-messaging host that sinotrans.com or y2t.com pages name, with no host allowlist.

This extension bridges web pages to a locally installed native app that signs transaction data with a smart card. Any page on the trusted sinotrans.com or y2t.com domains, including over a plain unencrypted http:// connection, can tell it which native host to connect to and what payload to send, and the extension forwards that verbatim without checking the host name against a fixed, expected value. The native app's replies are relayed straight back to the calling page.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

sinotrans.fev3.4.0.3Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 20 September 2026dhjdhmjlikofnjhlmapcpdakkahmbcdm