Is Malus VPN - The only official version safe?

Medium risk

Malus VPN is medium risk. Malus VPN's background worker reports a persistent device ID to GA on install, update, and each session; DA captured 11 POSTs (cid=6k268qv...). Tab-proxy events also send that tab's URL to GA and to api.getmalus.com with the plan type.

Malusv9.0.0Chrome Web Store
45Risk
Who publishes it

Malus - no other listings under this identity, 9 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Malus

Shared hosts - 9 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

stg-401.getmalus.com
Also called by 2 other listings, including Malus VPN
malus.app
Also called by 3 other listings, including Malus VPN
a.getmalus.cn
Also called by 4 other listings, including Unblock Bilibili
api.getmalus.com
Also called by 4 other listings, including Malus VPN, Unblock Bilibili
api.getmalus.net
Also called by 4 other listings, including Malus VPN, Unblock Bilibili
getmalus.com
Also called by 4 other listings
getmalus.net
Also called by 4 other listings
help.getmalus.com
Also called by 4 other listings, including Unblock Bilibili
ps-test.zoonode.com
Also called by 5 other listings

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Malus VPN Ties a Persistent Device ID to Sites You Unblock

Malus VPN's background worker reports a persistent device ID to GA on install, update, and each session; DA captured 11 POSTs (cid=6k268qv...).

Tab-proxy events also send that tab's URL to GA and to api.getmalus.com with the plan type.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install, update, or use Malus VPN, including letting it route a tab through its proxy.

The extension did this

The background service worker sends a GA event tagged with a persistent device ID; for proxied tabs it includes that tab's URL as the event label.

The same request() helper is reused for install, update, pageview, and per-URL proxy events, so every one of them carries the identical device ID.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.google-analytics.com/collect?v=1&tid=UA-92398359-3&cid=6k268qv35596mekkjdpb3c75&t=event&ec=chrome%2Fbackground&ea=install&el=&ev=undefined
204 No Content (standard Measurement Protocol collect acknowledgement, mode: no-cors so the body is opaque to the extension).
03EvidenceCODE COMPARE
The code that does this

The GA request builder, and the proxy-routing call site that feeds it a tab URL

What it actually does
request() -- readabledeobfuscated/static/js/background.js:4093-4109
class GaTracker {
  request(category, action, label, value) {
    const qs = `v=1&tid=${this.trackID}&cid=${this.userID}&t=event` +
      `&ec=${encodeURIComponent(category || "")}` +
      `&ea=${encodeURIComponent(action || "")}` +
      `&el=${encodeURIComponent(label || "")}` +
      `&ev=${value}`;
    fetch(`https://www.google-analytics.com/collect?${qs}`, { method: "POST", mode: "no-cors" });
  }
}
changeTabProxy() -> saveLog() -- readabledeobfuscated/static/js/background.js:497-510,4285-4297
changeTabProxy(tabId) {
  store.dispatch({ type: "tab", operate: "proxy", id: tabId, status: true });
  updateBadge();
  const { tab, user } = store.getState();
  const url = tab.tabs[tabId] && tab.tabs[tabId].url;
  if (url && url.startsWith("http")) api.saveLog(url, user.userType);
}

async function saveLog(url, userType) {
  gaTracker.backgroundEvent(`proxy/url/${userType}`, { label: url });
  this.post("saveLog", { body: { url, type: "PLAY" } });
}
04EvidenceFIELD TABLE
Fields sent to Google Analytics under the persistent device ID
FieldValueWhy it matters
Device ID
cid=6k268qv35596mekkjdpb3c75A UUID generated once and reused forever as the GA client ID, linking every event below to the same install over time.
Malus's GA property
tid=UA-92398359-3The Google Analytics tracking ID that all of Malus's own extension telemetry is grouped under.
Unblocked site URL
ea=proxy%2Furl%2Ffree&el=https%3A%2F%2Fwww.netflix.com%2Fbrowse (illustrative)When the extension proxies a tab, that tab's full URL is sent as the event label; this fires on every proxy/url and access/url event.
Account plan type
type="PLAY", userType="free"Whether the account is a guest, free, or paid user, sent alongside the URL in the extension's own saveLog API call.
05EvidenceTHIRD PARTY LIST
Where the device-ID-tagged events go
  • google-analytics.com

    Receives every install/update/pageview/proxy-routing event tagged with the persistent device ID, under Malus's own GA property. Operated by Google.

  • api.getmalus.com

    Malus's own backend; receives the same proxied-tab URL directly via the saveLog API, along with the account's plan type.

What it can do

Permissions this extension asks for, as declared in version 9.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Watch every request your browser makes

    webRequest

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Route all of your browsing through a server of its choosing

    proxy

webRequestAuthProvider
Updated 30 September 2026bdlcnpceagnkjnjlbbbcepohejbheilk