Is iGuge safe?
iGuge is medium risk. Enabling iGuge's VPN/proxy asks asia.igugehelperapi.com for a PAC script, adds the GeoIP list, and installs it as Chrome's PAC config, letting the server decide proxy routing. Without a login token this was skipped; confirmed post-login.
Who publishes itiGuguge Limited - no other listings under this identity, 5 shared hostnames
iGuguge Limited - no other listings under this identity, 5 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 5 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Remote PAC script controls browser proxy routing
Enabling iGuge's VPN/proxy asks asia.igugehelperapi.com for a PAC script, adds the GeoIP list, and installs it as Chrome's PAC config, letting the server decide proxy routing.
Without a login token this was skipped; confirmed post-login.
You enable the extension's VPN/proxy connection.
The connection flow requires a stored login token and selected server line before it continues.
The extension asks its service for PAC routing rules and installs the returned script as Chrome's proxy configuration.
The returned tpl value becomes the pacScript.data value with mandatory set to true.
| Field | Value | Why it matters | |
|---|---|---|---|
Selected proxy line | HK-SMART-01 (illustrative) | Tells the service which proxy line you selected before the routing script is returned. | |
GeoIP routing switch | true (illustrative) | Tells the service whether location-based routing should be reflected in the script applied to your browser. | |
Top-ranked proxy servers | [{"server":"HK-01","ranking":184,"result":"ok"}] (illustrative) | Adds local speed-test results that can influence which proxy servers are preferred for your browsing routes. | |
Extension account token | 9c8e4f6a1b2d3e70 (illustrative) | Lets the service associate the PAC request with the logged-in extension account on your browser. | |
Extension install identifier | ncldcbhpeplkfijdhnoepdgdnmjkckij | Identifies which extension install is making the PAC request. |
| Content-Type | application/json |
| Accept-Encoding | gzip |
PAC request and mandatory proxy installation
function get_base_domain() {
return "https://asia.igugehelperapi.com/";
}
function MZK_getJSON_DATA(API, send_data, _rcallback) {
if (!send_data)
send_data = {};
var Manifest = chrome.runtime.getManifest();
send_data.appver = Manifest.version;
send_data.device_name = iggcfg.mzk_config.device_name;
send_data.token = iggcfg.mzk_user_token;
send_data.curr_server_id = iggcfg.mzk_server_id;
send_data.runtime_id = chrome.runtime.id;
send_data.lang = iggcfg.mzk_config.lang;
if (iggcfg.mzk_user_info.is_vip) {
var curr_api_url = iggcfg.mzk_config.vip_base_domain;
if (!curr_api_url) curr_api_url = iggcfg.mzk_vip_backup_server[0];
iggcfg.curr_backup_server_list = iggcfg.mzk_vip_backup_server;
} else {
var curr_api_url = iggcfg.mzk_config.base_domain;
iggcfg.curr_backup_server_list = iggcfg.mzk_backup_server;
}
iggcfg.retryLimit = iggcfg.curr_backup_server_list.length;
getjsonData(curr_api_url, API, send_data, 0).then(data => {
if (!data) return false;
if (typeof data.msgtype !== "undefined" && typeof data.msgdata !== "undefined" && data.msgtype == "Encrypt") {
data = JSON.parse(CryptoJSAesDecrypt(data.msgdata));
}
if (_rcallback) {
_rcallback(data);
}
});
return true;
}
async function getjsonData(domain = '', apipath = '', data = {}, tryCount) {
const controller = new AbortController();
setTimeout(() => {
controller.abort();
}, 15000);
// Default options are marked with *
try {
if (!domain) domain = get_base_domain();
const response = await fetch(domain + apipath, {
method: 'POST', // *GET, POST, PUT, DELETE, etc.
mode: 'cors', // no-cors, *cors, same-origin
cache: 'no-cache', // *default, no-cache, reload, force-cache, only-if-cached
credentials: 'include', // include, *same-origin, omit
headers: {
'Content-Type': 'application/json',
'Accept-Encoding': 'gzip'
},
signal: controller.signal,
redirect: 'follow', // manual, *follow, error
referrerPolicy: 'origin', // no-referrer, *no-referrer-when-downgrade, origin, origin-when-cross-origin, same-origin, strict-origin-when-cross-origin, unsafe-url
body: JSON.stringify(data) // body data type must match "Content-Type" header
}).catch((error) => {
console.log(error)
});
return await response.json();
} catch (error) {
console.log(error);
if (tryCount < iggcfg.retryLimit) {
if (iggcfg.mzk_user_info.is_vip) iggcfg.mzk_config.vip_base_domain = iggcfg.curr_backup_server_list[tryCount]; else iggcfg.mzk_config.base_domain = iggcfg.curr_backup_server_list[tryCount];
domain = iggcfg.curr_backup_server_list[tryCount];
console.log("try domain:" + domain + apipath + " " + new Date());
chrome.storage.local.set({ last_api_domain: domain });
// chrome.storage.local.get(["debug_log"],function(r){
// var debug_log = [];
// if(typeof r.debug_log !== "undefined") debug_log = r.debug_log;
// var add_log = domain + apipath + " " + new Date();
// debug_log.push(add_log);
// chrome.storage.local.set("debug_log",debug_log);
// });
return getjsonData(domain, apipath, data, tryCount + 1);
} else {
if (!/getsession/igm.test(apipath) && !/show/igm.test(apipath) ) {
show_notifications_msg('network_error_' + Math.random(), get_lan_msg("error_network"));
}
return false;
}
}
}function open_vpn(_acallback) {
chrome.storage.local.get(["mzk_server_id", "mzk_select_server_info"], function (result) {
applyChanges('production', function () {
chrome.storage.local.set({ mzk_is_connect: true });
set_badge_on();
console.log('vpn Connected');
listen_server_auth();
if (_acallback)
_acallback();
});
});
}
function applyChanges(mode, cb) {
switch (iggcfg.mzk_config.device_name) {
case 'edge':
case 'chrome':
applyPacData(mode, cb);
break;
case 'firefox':
var browser_proxy = new Mzk_Firefox_proxy();
var base_domain = "";
if (iggcfg.mzk_user_info.is_vip) base_domain = iggcfg.mzk_config.vip_base_domain; else base_domain = iggcfg.mzk_config.base_domain;
var pac_url = base_domain + "chromeext/pac/show/token/" + mzk_user_token + "?sid=" + mzk_select_server_info.line_sn + "&pmode=" + mzk_connect_mode + "&geoip=" + mzk_pac_config.geoip_switch + "&rd=" + Math.random().toString();
var config = browser_proxy.generateProxyConfig(mode, pac_url);
var re = /HTTPS ([^;]+)/g;
var firefox_server = iggcfg.mzk_select_server_info.address.split(re);
var ff_info = firefox_server[1].split(":");
iggcfg.mzk_select_server_info.ff_server = { server: ff_info[0], port: ff_info[1] };
browser_proxy.applyChanges(config, cb);
break;
default:
}
}
function applyPacData(mode, cb) {
if ("production" === mode) {
chrome.storage.local.get(["testspeed_top_ranking_server", "mzk_token", "mzk_select_server_info"], function (s_server) {
iggcfg.mzk_user_token = s_server.mzk_token;
iggcfg.mzk_select_server_info = s_server.mzk_select_server_info;
var top_server = "";
if (iggcfg.mzk_select_server_info.line_mode == "smart" && s_server.testspeed_top_ranking_server) top_server = JSON.stringify(s_server.testspeed_top_ranking_server);
MZK_getJSON_DATA("chromeext/pac/show", { sid: iggcfg.mzk_select_server_info.line_sn, gpd: 1, geoip: iggcfg.mzk_pac_config.geoip_switch.toString(), top_server: top_server }, function (data) {
if (typeof data.result !== "undefined" && data.result == 'ok') {
load_default_data(function () {
var browser_proxy = new Mzk_Chrome_proxy();
data.tpl = data.tpl.replace('__GEOIP_LIST__', iggcfg.mzk_pac_config.geoip_data);
var config = browser_proxy.generateProxyConfig(mode, data.tpl);
browser_proxy.applyChanges(config, cb);
});
}else{
if (typeof data.result !== "undefined" && data.result == "error") {
show_notifications_msg('user_token_error', get_lan_msg("user_token_error"));
// user_logout();
}
}
});
});
} else {
var browser_proxy = new Mzk_Chrome_proxy();
var config = browser_proxy.generateProxyConfig(mode, '');
browser_proxy.applyChanges(config, cb);
}
}class Mzk_Chrome_proxy {
applyChanges(config, cb) {
chrome.proxy.settings.set({
value: config,
scope: 'regular'
}, cb);
}
generateProxyConfig(s_mode, pac_data) {
switch (s_mode) {
case 'system':
return { mode: 'system' }
case 'production':
if (pac_data)
return {
mode: 'pac_script',
pacScript: {
data: pac_data,
mandatory: true
}
}
}
return { mode: 'system' }
}
};- asia.igugehelperapi.com
Default API host that receives the PAC request and returns the script used for Chrome proxy routing.
- api.igg.fyi
VIP API host configured in the same request helper; VIP accounts can use this base URL for extension API calls.
What it can do
Permissions this extension asks for, as declared in version 2.3.9. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Show you desktop notifications
notifications
Store data in your browser
storage
Schedule its own background tasks
alarms
See, disable and uninstall your other extensions, including your security ones
management
Route all of your browsing through a server of its choosing
proxy
Watch every request your browser makes
webRequest
Detect when you step away from your computer
idle