Is max PayBack Reminder - מקס פייבק safe?

High risk

max PayBack is high risk. A static proof of concept shows this extension can enable or disable another installed extension via a matching message: app `lcc`/`lcc_website`, action `onOffExtention`, target ID, enabled state. DA didn't capture it firing live.

www.cashback.co.ilv2.2310.01.44Chrome Web Store
75Risk
Who publishes it

www.cashback.co.il - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
www.cashback.co.il

Same store account

1 other listing published from this account, 20k+ users between them. 1 of them carries a finding.

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

cashyo.co.il
Also called by 4 other listings, including mycashback.com.br
hotelscombined.co.il
Also called by 4 other listings, including mycashback.com.br

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-940
SourceAI SANDBOX

Extension message can toggle other installed extensions

A static proof of concept shows this extension can enable or disable another installed extension via a matching message: app `lcc`/`lcc_website`, action `onOffExtention`, target ID, enabled state.

DA didn't capture it firing live.

01EvidenceCAUSE EFFECT
What actually happens
You did this

A page event or widget request sends a command into the extension.

The command has to use the extension's expected app name and request the `onOffExtention` action.

The extension did this

The extension can turn another installed extension on or off.

The target extension ID and enabled state come directly from the message fields.

02EvidenceFIELD TABLE
Message fields that drive the extension toggle
FieldValueWhy it matters
Extension app name
lccThis value lets the command pass the extension's message filter.
Requested action
onOffExtentionThis tells the extension which built-in handler to run.
Target extension ID
cjpalhdlnbpafiamejdnhcphjbkeiagmThis selects which installed extension would be changed.
Requested state
falseThis decides whether the target extension is enabled or disabled.
Response routing ID
0.7394081246315842This lets the page or widget match the extension's response to the original request.
03EvidenceCODE COMPARE
The code that does this

The page-to-extension message bridge forwards event details

What it actually does
Widget helper creates an `lccFetchEvent` messagestatic/js/main.js
async function k(e) {
  let t = arguments.length > 1 && void 0 !== arguments[1] ? arguments[1] : () => {};
  if ("function" != typeof t) throw new Error("callback should be a function");
  if ("undefined" == typeof e) throw new Error("payload is undefined");
  let n = Math.random().toString();
  e.requestId = n;
  let r = "lcc";
  e.appName = r;
  let o = new CustomEvent(r + "FetchEvent", {
    detail: e
  });
  document.addEventListener(r + "RespEvent_" + n, (function e(o) {
    t(o.detail), document.removeEventListener(r + "RespEvent_" + n, e)
  })), document.dispatchEvent(o)
}
Injected bridge forwards document events to runtime messagingutils/injections/CommunicationSystem.js
async function injectCommunicationSystem() {
  let e = await storeDB.get("app_name") || await chrome.runtime.sendMessage({
    action: "getAppName"
  });
  window[e + "_communicationSystemInjected"] || (window[e + "_communicationSystemInjected"] = !0, document.addEventListener(e + "FetchEvent", (async t => {
    let n = await chrome.runtime.sendMessage(t.detail);
    var o = new CustomEvent(e + "RespEvent_" + n.requestId, {
      detail: n
    });
    document.dispatchEvent(o)
  })), document.addEventListener(e + "_websiteFetchEvent", (async t => {
    let n = await chrome.runtime.sendMessage(t.detail);
    var o = new CustomEvent(e + "_websiteRespEvent_" + n.requestId, {
      detail: n
    });
    document.dispatchEvent(o)
  })), chrome.runtime.onMessage.addListener(((e, t, n) => (window[e.action] && responseBuilder(n, window[e.action], e), !0))))
}
04EvidenceCODE COMPARE
The code that does this

The dispatcher accepts the action and calls Chrome management

What it actually does
Dispatcher selects a method from the message actionutils/ExtensionApi.js
chrome.runtime.onMessage.addListener(((e, t, a) => {
  try {
    if (e && (e.appName == APP_NAME || e.appName == APP_NAME + "_website")) {
      e.tab = t.tab;
      const i = helpers.ExtensionApi?.[e.action];
      return helpers.Utils.trace("ExtensionApi", e.action), "function" != typeof i ? (helpers.Utils.trace("ExtensionApi - unknown action", e.action), a({
        error: `Unknown action: ${e.action}`,
        requestId: e.requestId
      }), !1) : (responseBuilder(a, i, e), !0)
    }
    return !1
  } catch (t) {
    try {
      a({
        error: t?.message || String(t),
        requestId: e?.requestId
      })
    } catch {}
    return !1
  }
}));
Toggle handler passes message fields to Chromeutils/ExtensionApi.js
async onOffExtention(e) {
  return chrome.management.setEnabled(e.ext_id, e.state, (() => {})), {
    req: e
  }
}
05EvidenceTHIRD PARTY LIST
Hosts involved in the control and configuration path
  • api.pay-back.co.il

    Serves `ext1.0/data/config.json`, which the extension caches as configuration, and receives the installed-extension inventory through `ext1.0/user/setExtensions`.

  • www.pay-back.co.il

    The manifest allows pages under this host to connect to the extension through Chrome's external messaging permission.

What it can do

Permissions this extension asks for, as declared in version 3.2602.24.001. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2.2310.01.44, which we have not unpacked yet.

  • Read and change your data on every site you visit

    <all_urls>

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

  • See the address and title of every tab you have open

    tabs

  • See, disable and uninstall your other extensions, including your security ones

    management

Updated 30 September 2026lghkkfjealjkonheilkflengobdkiaeo