Is Menores Preços Dudu Rocha safe?

Medium risk

Menores Preços is medium risk. Our dynamic analysis confirmed the extension overwrites XMLHttpRequest on every page you visit, copying every request's body, including checkout data, into a variable other page scripts can also read.…

menoresprecos.duduv12.14.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

A page-wide hook copies every website's request bodies for the extension

Our dynamic analysis confirmed the extension overwrites XMLHttpRequest on every page you visit, copying every request's body, including checkout data, into a variable other page scripts can also read.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You visit any website; the extension's page script runs on load.

The extension did this

The script overwrites XMLHttpRequest.prototype.open and .send so every request made on that page has its URL and body copied into a page-wide variable it can read.

This applies to requests from the site itself and any other script on the page, not only the extension's own calls.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://falcon.useinsider.com/api/v2/log-tracking/hit/kabum
A third-party analytics request made by the shopping site itself. Its body was captured by the extension's hook and, once decoded, contained the full contents of the shopping cart.
03EvidenceFIELD TABLE
Cart contents recovered from the captured request
FieldValueWhy it matters
Product ID
904345The item in the cart.
Product name
Mouse Gamer sem Fio Attack Shark X11Full product title, in plain text.
Unit price / sale price
177.77 / 159.99Listed and discounted price of the item.
Quantity
1How many units are in the cart.
Cart total
159.99Total value of the cart at checkout.
04EvidenceCODE COMPARE
The code that does this

The hook that overwrites XMLHttpRequest

What it actually does
const installXhrHook = () => {
	const KEY_PROTO = "prototype";
	const KEY_OPEN = "open";
	const KEY_SEND = "send";

	const originalOpen = XMLHttpRequest[KEY_PROTO][KEY_OPEN];
	const originalSend = XMLHttpRequest[KEY_PROTO][KEY_SEND];

	window.capturedRequests = {}; // page-global, not extension-private

	XMLHttpRequest[KEY_PROTO][KEY_OPEN] = function(method, url) {
		this.requestUrl = url;
		originalOpen.apply(this, arguments);
	};

	XMLHttpRequest[KEY_PROTO][KEY_SEND] = function(body) {
		if (body) {
			window.capturedRequests[this.requestUrl] = body; // stores every request's body, keyed by URL
		}
		originalSend.apply(this, arguments);
	}
}

installXhrHook();
05EvidenceCODE COMPARE
The code that does this

The extension reading back a captured request

What it actually does
applyCoupon = async (couponInfo) => {
	const result = {};
	// read back everything the hook has captured so far
	const captured = await bridgeToPageContext({ storeKey: "ddr_irmaos" });
	const checkoutBody = captured["/api/checkout/carrinho"];
	if (!checkoutBody) return result;
	const cart = { ...JSON.parse(checkoutBody), coupon: [couponInfo.codigo] };
	const response = await postToStoreCheckout("https://www.kabum.com.br/api/checkout/carrinho", cart);
	if (response && response.coupon && response.coupon[0] && response.coupon[0].valid) {
		result.applied = true;
		result.discount = response.totals.coupon_discount;
	}
	return result;
}
06EvidenceARTIFACT
Check if you're affected

Paste into the DevTools console on any page to check whether this extension's page-global request store is present and see what it currently holds.

RequiresA Chromium browser with the extension installed and enabled
detect-xhr-hook.js · js
if (typeof window.ddr_irmaos === 'object' && window.ddr_irmaos !== null) {
  console.log('XHR interception store detected: window.ddr_irmaos');
  console.log('Captured request URLs:', Object.keys(window.ddr_irmaos));
  console.log('Full captured store:', window.ddr_irmaos);
} else {
  console.log('window.ddr_irmaos is not present on this page.');
}
How to run it
  1. 1
    Open DevTools (F12) on any page with the extension enabled.
  2. 2
    Open the Console tab.
  3. 3
    Paste the script and press Enter.
  4. 4
    If present, the store lists every XHR URL made so far, each mapped to its request body.
SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Product page views and a persistent install ID sent to the developer's server

We observed the extension send the product code, title, and page URL to its own backend on every product page you view, tagged with a persistent ID unique to your install.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open a product page on an online store, such as a listing on KaBuM.

The extension did this

The extension's background service worker automatically sends the product's code, title, and page URL to the developer's own server.

The request also carries a persistent identifier assigned to your install.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://menoresprecos.dudurochatec.com.br/actions/json/product?event=bg_searchProduct&codigo=904345&descricao=Mouse+Gamer+sem+Fio+Attack+Shark+X11&href=https://www.kabum.com.br/produto/904345
Confirms the SKU, product title, and page URL of the exact item viewed.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://menoresprecos.dudurochatec.com.br/barraextensao/conta_evento
Sent automatically on the same page view. The localid value stays constant across visits and events.
Body
idloja=35&event=product-show&url=https://www.kabum.com.br&localid=017-31ac09bb-efd3-f6b4-2cae-cc7c1fc59021&isxmode=production&isxversion=6.7.0&isxbrowser=chromium
04EvidenceFIELD TABLE
Fields sent to the developer's backend
FieldValueWhy it matters
Product code (SKU)
904345Identifies exactly which item you looked at.
Product title
Mouse Gamer sem Fio Attack Shark X11The full name of the product, sent in plain text.
Page URL
https://www.kabum.com.br/produto/904345The exact store page you were on.
Persistent install ID
017-31ac09bb-efd3-f6b4-2cae-cc7c1fc59021A fixed identifier for your install that ties every event back together over time.
Extension + browser version
isxversion=6.7.0, isxbrowser=chromiumWhich build of the extension and which browser you're running.
05EvidenceCODE COMPARE
The code that does this

Every request is tagged with the same persistent ID

What it actually does
Product-view handler (renamed)background.js
onMessage('bg_searchProduct', (payload, sender, sendResponse) => {
    // forwards payload straight to the backend
    dispatch(RemoteApi.getJson, 'actions/json/product', payload, sendResponse, { ttl: TTL_MEDIUM });
});
Request builder (renamed): every call gets the same IDbackground.js
RemoteApi.buildParams = async (params = {}) => {
    if (!params.localid) params.localid = await getOrCreateInstallId(); // persistent per-install ID
    if (!params.isxmode) params.isxmode = 'production';
    if (!params.isxversion) params.isxversion = EXT_BUILD_VERSION;
    if (!params.isxbrowser) params.isxbrowser = 'chromium';
    return Object.keys(params).map(k => k + '=' + encodeURIComponent(params[k])).join('&');
};
06EvidenceTHIRD PARTY LIST
Where this data goes
  • menoresprecos.dudurochatec.com.br

    The extension developer's own backend. Receives product-view events and the persistent install identifier; neither is mentioned in the Chrome Web Store listing.

What it can do

Permissions this extension asks for, as declared in version 12.14.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on menoresprecos.dudurochatec.com.br

    https://menoresprecos.dudurochatec.com.br/**/*

  • Sign you in with your Google account

    identity

Updated 30 September 2026caejdeplfmpbnhkppbbckfiipjefepci