Is iGuge safe?

Medium risk

iGuge is medium risk. Enabling iGuge's VPN/proxy asks asia.igugehelperapi.com for a PAC script, adds the GeoIP list, and installs it as Chrome's PAC config, letting the server decide proxy routing. Without a login token this was skipped; confirmed post-login.

iGuguge Limitedv2.3.9Chrome Web Store
45Risk
Who publishes it

iGuguge Limited - no other listings under this identity, 5 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
iGuguge Limited
Declared legal entity
iGuguge Limited
Registered contact
iGuge

Shared hosts - 5 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

api.igg.fyi
Also called by 2 other listings
igg.fyi
Also called by 2 other listings, including iGuge
igg.imsfast.net
Also called by 2 other listings, including iGuge
iguge.net
Also called by 2 other listings, including iGuge
iguge.xyz
Also called by 2 other listings, including iGuge

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Remote PAC script controls browser proxy routing

Enabling iGuge's VPN/proxy asks asia.igugehelperapi.com for a PAC script, adds the GeoIP list, and installs it as Chrome's PAC config, letting the server decide proxy routing.

Without a login token this was skipped; confirmed post-login.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You enable the extension's VPN/proxy connection.

The connection flow requires a stored login token and selected server line before it continues.

The extension did this

The extension asks its service for PAC routing rules and installs the returned script as Chrome's proxy configuration.

The returned tpl value becomes the pacScript.data value with mandatory set to true.

02EvidenceFIELD TABLE
Fields the source code sends to the PAC endpoint
FieldValueWhy it matters
Selected proxy line
HK-SMART-01 (illustrative)Tells the service which proxy line you selected before the routing script is returned.
GeoIP routing switch
true (illustrative)Tells the service whether location-based routing should be reflected in the script applied to your browser.
Top-ranked proxy servers
[{"server":"HK-01","ranking":184,"result":"ok"}] (illustrative)Adds local speed-test results that can influence which proxy servers are preferred for your browsing routes.
Extension account token
9c8e4f6a1b2d3e70 (illustrative)Lets the service associate the PAC request with the logged-in extension account on your browser.
Extension install identifier
ncldcbhpeplkfijdhnoepdgdnmjkckijIdentifies which extension install is making the PAC request.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://asia.igugehelperapi.com/chromeext/pac/show
Headers
Content-Typeapplication/json
Accept-Encodinggzip
04EvidenceCODE COMPARE
The code that does this

PAC request and mandatory proxy installation

What it actually does
Base API URL and JSON POST helperjs/iggservice.js
function get_base_domain() {
        return "https://asia.igugehelperapi.com/";
    }

    function MZK_getJSON_DATA(API, send_data, _rcallback) {
        if (!send_data)
            send_data = {};
        var Manifest = chrome.runtime.getManifest();
        send_data.appver = Manifest.version;
        send_data.device_name = iggcfg.mzk_config.device_name;
        send_data.token = iggcfg.mzk_user_token;
        send_data.curr_server_id = iggcfg.mzk_server_id;
        send_data.runtime_id = chrome.runtime.id;
        send_data.lang = iggcfg.mzk_config.lang;
        if (iggcfg.mzk_user_info.is_vip) {
            var curr_api_url = iggcfg.mzk_config.vip_base_domain;
            if (!curr_api_url) curr_api_url = iggcfg.mzk_vip_backup_server[0];
            iggcfg.curr_backup_server_list = iggcfg.mzk_vip_backup_server;
        } else {
            var curr_api_url = iggcfg.mzk_config.base_domain;
            iggcfg.curr_backup_server_list = iggcfg.mzk_backup_server;
        }
        iggcfg.retryLimit = iggcfg.curr_backup_server_list.length;
        getjsonData(curr_api_url, API, send_data, 0).then(data => {
            if (!data) return false;
            if (typeof data.msgtype !== "undefined" && typeof data.msgdata !== "undefined" && data.msgtype == "Encrypt") {
                data = JSON.parse(CryptoJSAesDecrypt(data.msgdata));
            }
            if (_rcallback) {
                _rcallback(data);
            }
        });
        return true;
    }

    async function getjsonData(domain = '', apipath = '', data = {}, tryCount) {
        const controller = new AbortController();
        setTimeout(() => {
            controller.abort();
        }, 15000);
        // Default options are marked with *
        try {
            if (!domain) domain = get_base_domain();
            const response = await fetch(domain + apipath, {
                method: 'POST', // *GET, POST, PUT, DELETE, etc.
                mode: 'cors', // no-cors, *cors, same-origin
                cache: 'no-cache', // *default, no-cache, reload, force-cache, only-if-cached
                credentials: 'include', // include, *same-origin, omit
                headers: {
                    'Content-Type': 'application/json',
                    'Accept-Encoding': 'gzip'
                },
                signal: controller.signal,
                redirect: 'follow', // manual, *follow, error
                referrerPolicy: 'origin', // no-referrer, *no-referrer-when-downgrade, origin, origin-when-cross-origin, same-origin, strict-origin-when-cross-origin, unsafe-url
                body: JSON.stringify(data) // body data type must match "Content-Type" header
            }).catch((error) => {
                console.log(error)
            });
            return await response.json();
        } catch (error) {
            console.log(error);
            if (tryCount < iggcfg.retryLimit) {
                if (iggcfg.mzk_user_info.is_vip) iggcfg.mzk_config.vip_base_domain = iggcfg.curr_backup_server_list[tryCount]; else iggcfg.mzk_config.base_domain = iggcfg.curr_backup_server_list[tryCount];
                domain = iggcfg.curr_backup_server_list[tryCount];
                console.log("try domain:" + domain +  apipath + " " + new Date());
                chrome.storage.local.set({ last_api_domain: domain });
                // chrome.storage.local.get(["debug_log"],function(r){
                //     var debug_log = [];
                //     if(typeof r.debug_log !== "undefined") debug_log = r.debug_log;
                //     var add_log = domain + apipath + " " + new Date();
                //     debug_log.push(add_log);
                //     chrome.storage.local.set("debug_log",debug_log);
                // });
                return getjsonData(domain, apipath, data, tryCount + 1);
            } else {
                if (!/getsession/igm.test(apipath) && !/show/igm.test(apipath) ) {
                    show_notifications_msg('network_error_' + Math.random(), get_lan_msg("error_network"));
                }
                return false;
            }
        }
    }
Connection flow asks for PAC datajs/iggservice.js
function open_vpn(_acallback) {
        chrome.storage.local.get(["mzk_server_id", "mzk_select_server_info"], function (result) {
            applyChanges('production', function () {
                chrome.storage.local.set({ mzk_is_connect: true });
                set_badge_on();
                console.log('vpn Connected');
                listen_server_auth();
                if (_acallback)
                    _acallback();
            });
        });
    }

    function applyChanges(mode, cb) {
        switch (iggcfg.mzk_config.device_name) {
            case 'edge':
            case 'chrome':
                applyPacData(mode, cb);
                break;
            case 'firefox':
                var browser_proxy = new Mzk_Firefox_proxy();
                var base_domain = "";
                if (iggcfg.mzk_user_info.is_vip) base_domain = iggcfg.mzk_config.vip_base_domain; else base_domain = iggcfg.mzk_config.base_domain;
                var pac_url = base_domain + "chromeext/pac/show/token/" + mzk_user_token + "?sid=" + mzk_select_server_info.line_sn + "&pmode=" + mzk_connect_mode + "&geoip=" + mzk_pac_config.geoip_switch + "&rd=" + Math.random().toString();
                var config = browser_proxy.generateProxyConfig(mode, pac_url);
                var re = /HTTPS ([^;]+)/g;
                var firefox_server = iggcfg.mzk_select_server_info.address.split(re);
                var ff_info = firefox_server[1].split(":");
                iggcfg.mzk_select_server_info.ff_server = { server: ff_info[0], port: ff_info[1] };
                browser_proxy.applyChanges(config, cb);
                break;
            default:
        }
    }

    function applyPacData(mode, cb) {
        if ("production" === mode) {
            chrome.storage.local.get(["testspeed_top_ranking_server", "mzk_token", "mzk_select_server_info"], function (s_server) {
                iggcfg.mzk_user_token = s_server.mzk_token;
                iggcfg.mzk_select_server_info = s_server.mzk_select_server_info;
                var top_server = "";
                if (iggcfg.mzk_select_server_info.line_mode == "smart" && s_server.testspeed_top_ranking_server) top_server = JSON.stringify(s_server.testspeed_top_ranking_server);
                MZK_getJSON_DATA("chromeext/pac/show", { sid: iggcfg.mzk_select_server_info.line_sn, gpd: 1, geoip: iggcfg.mzk_pac_config.geoip_switch.toString(), top_server: top_server }, function (data) {
                    if (typeof data.result !== "undefined" && data.result == 'ok') {
                        load_default_data(function () {
                            var browser_proxy = new Mzk_Chrome_proxy();
                            data.tpl = data.tpl.replace('__GEOIP_LIST__', iggcfg.mzk_pac_config.geoip_data);
                            var config = browser_proxy.generateProxyConfig(mode, data.tpl);
                            browser_proxy.applyChanges(config, cb);
                        });
                    }else{
                        if (typeof data.result !== "undefined" && data.result == "error") {
                            show_notifications_msg('user_token_error', get_lan_msg("user_token_error"));
                            // user_logout();
                        }
                    }
                });
            });
        } else {
            var browser_proxy = new Mzk_Chrome_proxy();
            var config = browser_proxy.generateProxyConfig(mode, '');
            browser_proxy.applyChanges(config, cb);
        }
    }
Returned script becomes mandatory Chrome proxy configurationjs/iggservice.js
class Mzk_Chrome_proxy {
        applyChanges(config, cb) {
            chrome.proxy.settings.set({
                value: config,
                scope: 'regular'
            }, cb);
        }

        generateProxyConfig(s_mode, pac_data) {
            switch (s_mode) {
                case 'system':
                    return { mode: 'system' }
                case 'production':
                    if (pac_data)
                        return {
                            mode: 'pac_script',
                            pacScript: {
                                data: pac_data,
                                mandatory: true
                            }
                        }
            }
            return { mode: 'system' }
        }
    };
05EvidenceTHIRD PARTY LIST
Hosts involved in the PAC routing flow
  • asia.igugehelperapi.com

    Default API host that receives the PAC request and returns the script used for Chrome proxy routing.

  • api.igg.fyi

    VIP API host configured in the same request helper; VIP accounts can use this base URL for extension API calls.

What it can do

Permissions this extension asks for, as declared in version 2.3.9. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Show you desktop notifications

    notifications

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

  • See, disable and uninstall your other extensions, including your security ones

    management

  • Route all of your browsing through a server of its choosing

    proxy

  • Watch every request your browser makes

    webRequest

  • Detect when you step away from your computer

    idle

webRequestAuthProvider
Updated 30 September 2026ncldcbhpeplkfijdhnoepdgdnmjkckij