Is CFCA CryptoKit.XMYLSW Extension safe?

Low risk

CFCA CryptoKit.XMYLSW Extension lets any xmztb.com page pick the native-messaging host and payload it forwards, with no allowlist.

This extension bridges bank pages on xmztb.com to a locally installed smart-card signing application via Chrome's native messaging. When a page on that domain sends a connect request, the extension passes the page-supplied host name straight to chrome.runtime.connectNative() and later relays the page-supplied payload to whichever native program that connects, without checking it against a fixed vendor host or command list. The domain is allowed over both https and unencrypted http, so the same bridge is reachable from a plaintext connection to the bank's site.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

CFCACryptoKitv3.4.0.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

locally-installed native messaging host (device-side, not a remote server)
Updated 20 September 2026ldfdgjpgabhpfdcepajhggdimphldhom