Is max PayBack Reminder - מקס פייבק safe?
max PayBack is high risk. A static proof of concept shows this extension can enable or disable another installed extension via a matching message: app `lcc`/`lcc_website`, action `onOffExtention`, target ID, enabled state. DA didn't capture it firing live.
Who publishes itwww.cashback.co.il - 1 other listing from the same operator, 1 of them carrying a finding
www.cashback.co.il - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 20k+ users between them. 1 of them carries a finding.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension message can toggle other installed extensions
A static proof of concept shows this extension can enable or disable another installed extension via a matching message: app `lcc`/`lcc_website`, action `onOffExtention`, target ID, enabled state.
DA didn't capture it firing live.
A page event or widget request sends a command into the extension.
The command has to use the extension's expected app name and request the `onOffExtention` action.
The extension can turn another installed extension on or off.
The target extension ID and enabled state come directly from the message fields.
| Field | Value | Why it matters | |
|---|---|---|---|
Extension app name | lcc | This value lets the command pass the extension's message filter. | |
Requested action | onOffExtention | This tells the extension which built-in handler to run. | |
Target extension ID | cjpalhdlnbpafiamejdnhcphjbkeiagm | This selects which installed extension would be changed. | |
Requested state | false | This decides whether the target extension is enabled or disabled. | |
Response routing ID | 0.7394081246315842 | This lets the page or widget match the extension's response to the original request. |
The page-to-extension message bridge forwards event details
async function k(e) {
let t = arguments.length > 1 && void 0 !== arguments[1] ? arguments[1] : () => {};
if ("function" != typeof t) throw new Error("callback should be a function");
if ("undefined" == typeof e) throw new Error("payload is undefined");
let n = Math.random().toString();
e.requestId = n;
let r = "lcc";
e.appName = r;
let o = new CustomEvent(r + "FetchEvent", {
detail: e
});
document.addEventListener(r + "RespEvent_" + n, (function e(o) {
t(o.detail), document.removeEventListener(r + "RespEvent_" + n, e)
})), document.dispatchEvent(o)
}async function injectCommunicationSystem() {
let e = await storeDB.get("app_name") || await chrome.runtime.sendMessage({
action: "getAppName"
});
window[e + "_communicationSystemInjected"] || (window[e + "_communicationSystemInjected"] = !0, document.addEventListener(e + "FetchEvent", (async t => {
let n = await chrome.runtime.sendMessage(t.detail);
var o = new CustomEvent(e + "RespEvent_" + n.requestId, {
detail: n
});
document.dispatchEvent(o)
})), document.addEventListener(e + "_websiteFetchEvent", (async t => {
let n = await chrome.runtime.sendMessage(t.detail);
var o = new CustomEvent(e + "_websiteRespEvent_" + n.requestId, {
detail: n
});
document.dispatchEvent(o)
})), chrome.runtime.onMessage.addListener(((e, t, n) => (window[e.action] && responseBuilder(n, window[e.action], e), !0))))
}The dispatcher accepts the action and calls Chrome management
chrome.runtime.onMessage.addListener(((e, t, a) => {
try {
if (e && (e.appName == APP_NAME || e.appName == APP_NAME + "_website")) {
e.tab = t.tab;
const i = helpers.ExtensionApi?.[e.action];
return helpers.Utils.trace("ExtensionApi", e.action), "function" != typeof i ? (helpers.Utils.trace("ExtensionApi - unknown action", e.action), a({
error: `Unknown action: ${e.action}`,
requestId: e.requestId
}), !1) : (responseBuilder(a, i, e), !0)
}
return !1
} catch (t) {
try {
a({
error: t?.message || String(t),
requestId: e?.requestId
})
} catch {}
return !1
}
}));async onOffExtention(e) {
return chrome.management.setEnabled(e.ext_id, e.state, (() => {})), {
req: e
}
}- api.pay-back.co.il
Serves `ext1.0/data/config.json`, which the extension caches as configuration, and receives the installed-extension inventory through `ext1.0/user/setExtensions`.
- www.pay-back.co.il
The manifest allows pages under this host to connect to the extension through Chrome's external messaging permission.
What it can do
Permissions this extension asks for, as declared in version 3.2602.24.001. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2.2310.01.44, which we have not unpacked yet.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Run its own code inside the pages you visit
scripting
See the address and title of every tab you have open
tabs
See, disable and uninstall your other extensions, including your security ones
management