Is CFCA CryptoKit.SRCBSCF Extension safe?

Low risk

CFCA CryptoKit.SRCBSCF Extension bridges CFCA-affiliated banking pages to a local native messaging host for cryptographic operations.

The extension acts as a relay between CFCA-affiliated bank websites (*.srcb.com, *.shrcb.com) and a locally installed native application that handles cryptographic functions such as digital signing. Pages on those domains send messages to the extension specifying which native host to connect to and which cryptographic operations to perform. The caller-supplied native host name is passed directly to chrome.runtime.connectNative() without an allowlist check, meaning any page on the permitted domains — or an XSS on them — could direct the extension to attempt a connection to an arbitrary installed native messaging host.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

developer.srcbv3.4.1.0Chrome Web Store
20Risk
Who publishes it

developer.srcb - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
developer.srcb

Same store account

3 other listings published from this account, 70k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.4.1.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on srcb.com

    https://*.srcb.com/*

  • Read and change your data on shrcb.com

    https://*.shrcb.com/* and 1 more

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026beipgeecjeblcbbejgddhobloclplfge