Is 芒果店长 safe?
芒果店长 is high risk. The extension sends the page URL to fetch.mangoerp.com/parse/identify and gets a JS detection string for Amazon pages. That string is passed into chrome.scripting.executeScript and run in the tab, giving server code page access.…
Who publishes it富通天下云技术团队 - 1 other listing from the same operator, none carrying a finding
富通天下云技术团队 - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 6k+ users between them, none of them carrying a finding.
Shared hosts - 7 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Remote JavaScript from Mango ERP runs in visited tabs
The extension sends the page URL to fetch.mangoerp.com/parse/identify and gets a JS detection string for Amazon pages.
That string is passed into chrome.scripting.executeScript and run in the tab, giving server code page access.
You open a supported webpage in Chrome.
The content script is configured to run on both HTTP and HTTPS pages, except for a small set of excluded local and Mango ERP pages.
The extension asks a Mango ERP endpoint for a detection script and runs the returned JavaScript in the tab.
The code only executes the returned value when the response includes a non-empty detect string.
| Field | Value | Why it matters | |
|---|---|---|---|
Visited page URL | https://www.amazon.com/ | The remote endpoint receives the page address, so browsing activity can be associated with the server response. | |
Returned detection script | data.detect JavaScript returned for an Amazon page | When this field is present, the extension treats it as JavaScript to run in the page you are viewing. | |
Execution parameter | type: localhref; params: https://www.amazon.com/ | The current page address is passed into the returned script while it runs in the tab. |
The content script requests server code; the background worker executes it
function T() {
return $(".mango-link-next").each((function(e, t) {
$(t).remove()
})), "www.17qcc.com" === location.host ? (-1 !== location.href.indexOf("/item/") && (chrome.runtime.sendMessage({
ID: "background",
action: "preload",
type: "single",
isShowMenus: !0
}), X("single")), !1) : location.host.includes("tiktok.com") ? ((location.href.indexOf(/product/) > -1 || location.href.indexOf("/pdp/") > -1) && (chrome.runtime.sendMessage({
ID: "background",
action: "preload",
type: "single"
}), X("single")), !1) : void chrome.runtime.sendMessage({
ID: "background",
action: "identify"
}, (function(t) {
t && t.success && (e = t.data).detect && chrome.runtime.sendMessage({
ID: "background",
action: "execute",
config: {
detect: e.detect,
params: location.href,
type: "localhref"
}
}, (function(t) {
console.log(t);
var a = t;
try {
var i = e.map[a];
i && (n.showPageFetchBar && X(i), chrome.runtime.sendMessage({
ID: "background",
action: "preload",
type: i,
isShowMenus: !/(taobao|tmall)\.(com|hk)$/.test(location.host)
})), M(e.detail), $(window).scroll(m)
} catch (e) {
console.log(e)
}
}))
}))
}function h(e, t, i) {
return "localhref" === t ? new eval5.Function("$", "url", e)($, i) : "element" === t ? new eval5.Function("$el", e) : "url" === t ? new eval5.Function("url", e)(i) : new eval5.Function(e)()
}
chrome.runtime.onMessage.addListener((function(e, n, m) {
if ("background" !== e.ID) return;
var v = n.tab.url;
v.indexOf("jinritemai.com") > -1 && (v = v.split("&")[0]);
const w = l.find((e => e.tabId == n.tab.id || e.tabId == n.tab.windowId));
switch (e.action) {
case "identify":
return !v.includes("//seller.shopee.cn/webchat/conversations") && (fetch("https://fetch.mangoerp.com/parse/identify?url=" + encodeURIComponent(v)).then((e => e.json())).then((function(e) {
if (m(e), e.success) {
var i = e.data.referrer;
if (i) i.split(",").forEach((function(e) {
t.includes(e) || t.push(e)
}))
}
})), !0);
case "execute":
return async function(e, t, i, n) {
i.detect && "string" == typeof i.detect && chrome.scripting.executeScript({
target: {
tabId: e
},
func: t,
args: [i.detect, i.type || "", i.params || ""]
}, (e => {
n && e && e.length > 0 && n(e[0].result)
}))
}(n.tab.id, h, e.config, (function(e) {
m(e)
})), !0
}
}))- fetch.mangoerp.com
Receives the visited page URL and returns the detection-script response used by the extension.
Current tab URL sent to MangoERP server on every page navigation
When you navigate to a page, the extension sends the current tab URL to fetch.mangoerp.com.
This can expose browsing history across websites because the request is triggered automatically on page navigation.
You navigate to a page in the browser.
The extension sends the current tab URL to fetch.mangoerp.com for page identification.
| Field | Value | Why it matters | |
|---|---|---|---|
Current tab URL | https://www.example.com/account | Shows the exact page you are visiting when the extension runs. | |
Browsing history | https://www.example.com/search?q=order-status | Repeated navigation-triggered requests can reveal a sequence of sites visited over time. |
Dynamic analysis observed requests to this endpoint with visited URLs in the query string, confirming the URL transmission behavior.