Is Malus VPN - The only official version safe?
Malus VPN is medium risk. Malus VPN's background worker reports a persistent device ID to GA on install, update, and each session; DA captured 11 POSTs (cid=6k268qv...). Tab-proxy events also send that tab's URL to GA and to api.getmalus.com with the plan type.
Who publishes itMalus - no other listings under this identity, 9 shared hostnames
Malus - no other listings under this identity, 9 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 9 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Malus VPN Ties a Persistent Device ID to Sites You Unblock
Malus VPN's background worker reports a persistent device ID to GA on install, update, and each session; DA captured 11 POSTs (cid=6k268qv...).
Tab-proxy events also send that tab's URL to GA and to api.getmalus.com with the plan type.
You install, update, or use Malus VPN, including letting it route a tab through its proxy.
The background service worker sends a GA event tagged with a persistent device ID; for proxied tabs it includes that tab's URL as the event label.
The same request() helper is reused for install, update, pageview, and per-URL proxy events, so every one of them carries the identical device ID.
The GA request builder, and the proxy-routing call site that feeds it a tab URL
class GaTracker {
request(category, action, label, value) {
const qs = `v=1&tid=${this.trackID}&cid=${this.userID}&t=event` +
`&ec=${encodeURIComponent(category || "")}` +
`&ea=${encodeURIComponent(action || "")}` +
`&el=${encodeURIComponent(label || "")}` +
`&ev=${value}`;
fetch(`https://www.google-analytics.com/collect?${qs}`, { method: "POST", mode: "no-cors" });
}
}changeTabProxy(tabId) {
store.dispatch({ type: "tab", operate: "proxy", id: tabId, status: true });
updateBadge();
const { tab, user } = store.getState();
const url = tab.tabs[tabId] && tab.tabs[tabId].url;
if (url && url.startsWith("http")) api.saveLog(url, user.userType);
}
async function saveLog(url, userType) {
gaTracker.backgroundEvent(`proxy/url/${userType}`, { label: url });
this.post("saveLog", { body: { url, type: "PLAY" } });
}| Field | Value | Why it matters | |
|---|---|---|---|
Device ID | cid=6k268qv35596mekkjdpb3c75 | A UUID generated once and reused forever as the GA client ID, linking every event below to the same install over time. | |
Malus's GA property | tid=UA-92398359-3 | The Google Analytics tracking ID that all of Malus's own extension telemetry is grouped under. | |
Unblocked site URL | ea=proxy%2Furl%2Ffree&el=https%3A%2F%2Fwww.netflix.com%2Fbrowse (illustrative) | When the extension proxies a tab, that tab's full URL is sent as the event label; this fires on every proxy/url and access/url event. | |
Account plan type | type="PLAY", userType="free" | Whether the account is a guest, free, or paid user, sent alongside the URL in the extension's own saveLog API call. |
- google-analytics.com
Receives every install/update/pageview/proxy-routing event tagged with the persistent device ID, under Malus's own GA property. Operated by Google.
- api.getmalus.com
Malus's own backend; receives the same proxied-tab URL directly via the saveLog API, along with the account's plan type.
What it can do
Permissions this extension asks for, as declared in version 9.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
Watch every request your browser makes
webRequest
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Route all of your browsing through a server of its choosing
proxy