Is CFCA CryptoKit.XMYLSW Extension safe?
CFCA CryptoKit.XMYLSW Extension lets any xmztb.com page pick the native-messaging host and payload it forwards, with no allowlist.
This extension bridges bank pages on xmztb.com to a locally installed smart-card signing application via Chrome's native messaging. When a page on that domain sends a connect request, the extension passes the page-supplied host name straight to chrome.runtime.connectNative() and later relays the page-supplied payload to whichever native program that connects, without checking it against a fixed vendor host or command list. The domain is allowed over both https and unencrypted http, so the same bridge is reachable from a plaintext connection to the bank's site.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.