Is 芒果店长 safe?

High risk

芒果店长 is high risk. The extension sends the page URL to fetch.mangoerp.com/parse/identify and gets a JS detection string for Amazon pages. That string is passed into chrome.scripting.executeScript and run in the tab, giving server code page access.…

富通天下云技术团队v2.0.8Chrome Web Store
75Risk
Who publishes it

富通天下云技术团队 - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
富通天下云技术团队

Same store account

1 other listing published from this account, 6k+ users between them, none of them carrying a finding.

Shared hosts - 7 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

h5api.m.tmall.hk
Also called by 1 other listing: ozon bang
fetch.mangoerp.com
Also called by 3 other listings, including 芒果店长
d.3.cn
Also called by 4 other listings, including 芒果店长
ns.mangoerp.com
Also called by 4 other listings, including 芒果店长
kilimall.co.ug
Also called by 5 other listings
lazada.com.th
Also called by 5 other listings, including 芒果店长
mangoerp.com
Also called by 5 other listings

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Remote JavaScript from Mango ERP runs in visited tabs

The extension sends the page URL to fetch.mangoerp.com/parse/identify and gets a JS detection string for Amazon pages.

That string is passed into chrome.scripting.executeScript and run in the tab, giving server code page access.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open a supported webpage in Chrome.

The content script is configured to run on both HTTP and HTTPS pages, except for a small set of excluded local and Mango ERP pages.

The extension did this

The extension asks a Mango ERP endpoint for a detection script and runs the returned JavaScript in the tab.

The code only executes the returned value when the response includes a non-empty detect string.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://fetch.mangoerp.com/parse/identify?url=https%3A%2F%2Fwww.amazon.com%2F
JSON response containing data.detect JavaScript was observed for an Amazon page.
03EvidenceFIELD TABLE
Fields used to request and execute the remote detection script
FieldValueWhy it matters
Visited page URL
https://www.amazon.com/The remote endpoint receives the page address, so browsing activity can be associated with the server response.
Returned detection script
data.detect JavaScript returned for an Amazon pageWhen this field is present, the extension treats it as JavaScript to run in the page you are viewing.
Execution parameter
type: localhref; params: https://www.amazon.com/The current page address is passed into the returned script while it runs in the tab.
04EvidenceCODE COMPARE
The code that does this

The content script requests server code; the background worker executes it

What it actually does
content.js requests identify, then executedeobfuscated/content.js
function T() {
  return $(".mango-link-next").each((function(e, t) {
    $(t).remove()
  })), "www.17qcc.com" === location.host ? (-1 !== location.href.indexOf("/item/") && (chrome.runtime.sendMessage({
    ID: "background",
    action: "preload",
    type: "single",
    isShowMenus: !0
  }), X("single")), !1) : location.host.includes("tiktok.com") ? ((location.href.indexOf(/product/) > -1 || location.href.indexOf("/pdp/") > -1) && (chrome.runtime.sendMessage({
    ID: "background",
    action: "preload",
    type: "single"
  }), X("single")), !1) : void chrome.runtime.sendMessage({
    ID: "background",
    action: "identify"
  }, (function(t) {
    t && t.success && (e = t.data).detect && chrome.runtime.sendMessage({
      ID: "background",
      action: "execute",
      config: {
        detect: e.detect,
        params: location.href,
        type: "localhref"
      }
    }, (function(t) {
      console.log(t);
      var a = t;
      try {
        var i = e.map[a];
        i && (n.showPageFetchBar && X(i), chrome.runtime.sendMessage({
          ID: "background",
          action: "preload",
          type: i,
          isShowMenus: !/(taobao|tmall)\.(com|hk)$/.test(location.host)
        })), M(e.detail), $(window).scroll(m)
      } catch (e) {
        console.log(e)
      }
    }))
  }))
}
background.js fetches identify response and executes detectdeobfuscated/background.js
function h(e, t, i) {
  return "localhref" === t ? new eval5.Function("$", "url", e)($, i) : "element" === t ? new eval5.Function("$el", e) : "url" === t ? new eval5.Function("url", e)(i) : new eval5.Function(e)()
}
chrome.runtime.onMessage.addListener((function(e, n, m) {
  if ("background" !== e.ID) return;
  var v = n.tab.url;
  v.indexOf("jinritemai.com") > -1 && (v = v.split("&")[0]);
  const w = l.find((e => e.tabId == n.tab.id || e.tabId == n.tab.windowId));
  switch (e.action) {
    case "identify":
      return !v.includes("//seller.shopee.cn/webchat/conversations") && (fetch("https://fetch.mangoerp.com/parse/identify?url=" + encodeURIComponent(v)).then((e => e.json())).then((function(e) {
        if (m(e), e.success) {
          var i = e.data.referrer;
          if (i) i.split(",").forEach((function(e) {
            t.includes(e) || t.push(e)
          }))
        }
      })), !0);
    case "execute":
      return async function(e, t, i, n) {
        i.detect && "string" == typeof i.detect && chrome.scripting.executeScript({
          target: {
            tabId: e
          },
          func: t,
          args: [i.detect, i.type || "", i.params || ""]
        }, (e => {
          n && e && e.length > 0 && n(e[0].result)
        }))
      }(n.tab.id, h, e.config, (function(e) {
        m(e)
      })), !0
  }
}))
05EvidenceTHIRD PARTY LIST
External host involved in this flow
  • fetch.mangoerp.com

    Receives the visited page URL and returns the detection-script response used by the extension.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Current tab URL sent to MangoERP server on every page navigation

When you navigate to a page, the extension sends the current tab URL to fetch.mangoerp.com.

This can expose browsing history across websites because the request is triggered automatically on page navigation.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to a page in the browser.

The extension did this

The extension sends the current tab URL to fetch.mangoerp.com for page identification.

02EvidenceNETWORK CAPTURE
Captured request
GETfetch.mangoerp.com/parse/identify
03EvidenceFIELD TABLE
Fields in the request
FieldValueWhy it matters
Current tab URL
https://www.example.com/accountShows the exact page you are visiting when the extension runs.
Browsing history
https://www.example.com/search?q=order-statusRepeated navigation-triggered requests can reveal a sequence of sites visited over time.
04EvidencePLAIN NOTE
Observation

Dynamic analysis observed requests to this endpoint with visited URLs in the query string, confirming the URL transmission behavior.

Updated 30 September 2026imjfokfjjgpijjfgnodojafbkoonmmkh