Is Menores Preços Dudu Rocha safe?
Menores Preços is medium risk. Our dynamic analysis confirmed the extension overwrites XMLHttpRequest on every page you visit, copying every request's body, including checkout data, into a variable other page scripts can also read.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
A page-wide hook copies every website's request bodies for the extension
Our dynamic analysis confirmed the extension overwrites XMLHttpRequest on every page you visit, copying every request's body, including checkout data, into a variable other page scripts can also read.
You visit any website; the extension's page script runs on load.
The script overwrites XMLHttpRequest.prototype.open and .send so every request made on that page has its URL and body copied into a page-wide variable it can read.
This applies to requests from the site itself and any other script on the page, not only the extension's own calls.
| Field | Value | Why it matters | |
|---|---|---|---|
Product ID | 904345 | The item in the cart. | |
Product name | Mouse Gamer sem Fio Attack Shark X11 | Full product title, in plain text. | |
Unit price / sale price | 177.77 / 159.99 | Listed and discounted price of the item. | |
Quantity | 1 | How many units are in the cart. | |
Cart total | 159.99 | Total value of the cart at checkout. |
The hook that overwrites XMLHttpRequest
const installXhrHook = () => {
const KEY_PROTO = "prototype";
const KEY_OPEN = "open";
const KEY_SEND = "send";
const originalOpen = XMLHttpRequest[KEY_PROTO][KEY_OPEN];
const originalSend = XMLHttpRequest[KEY_PROTO][KEY_SEND];
window.capturedRequests = {}; // page-global, not extension-private
XMLHttpRequest[KEY_PROTO][KEY_OPEN] = function(method, url) {
this.requestUrl = url;
originalOpen.apply(this, arguments);
};
XMLHttpRequest[KEY_PROTO][KEY_SEND] = function(body) {
if (body) {
window.capturedRequests[this.requestUrl] = body; // stores every request's body, keyed by URL
}
originalSend.apply(this, arguments);
}
}
installXhrHook();The extension reading back a captured request
applyCoupon = async (couponInfo) => {
const result = {};
// read back everything the hook has captured so far
const captured = await bridgeToPageContext({ storeKey: "ddr_irmaos" });
const checkoutBody = captured["/api/checkout/carrinho"];
if (!checkoutBody) return result;
const cart = { ...JSON.parse(checkoutBody), coupon: [couponInfo.codigo] };
const response = await postToStoreCheckout("https://www.kabum.com.br/api/checkout/carrinho", cart);
if (response && response.coupon && response.coupon[0] && response.coupon[0].valid) {
result.applied = true;
result.discount = response.totals.coupon_discount;
}
return result;
}Paste into the DevTools console on any page to check whether this extension's page-global request store is present and see what it currently holds.
if (typeof window.ddr_irmaos === 'object' && window.ddr_irmaos !== null) {
console.log('XHR interception store detected: window.ddr_irmaos');
console.log('Captured request URLs:', Object.keys(window.ddr_irmaos));
console.log('Full captured store:', window.ddr_irmaos);
} else {
console.log('window.ddr_irmaos is not present on this page.');
}- 1Open DevTools (F12) on any page with the extension enabled.
- 2Open the Console tab.
- 3Paste the script and press Enter.
- 4If present, the store lists every XHR URL made so far, each mapped to its request body.
Product page views and a persistent install ID sent to the developer's server
We observed the extension send the product code, title, and page URL to its own backend on every product page you view, tagged with a persistent ID unique to your install.
You open a product page on an online store, such as a listing on KaBuM.
The extension's background service worker automatically sends the product's code, title, and page URL to the developer's own server.
The request also carries a persistent identifier assigned to your install.
idloja=35&event=product-show&url=https://www.kabum.com.br&localid=017-31ac09bb-efd3-f6b4-2cae-cc7c1fc59021&isxmode=production&isxversion=6.7.0&isxbrowser=chromium
| Field | Value | Why it matters | |
|---|---|---|---|
Product code (SKU) | 904345 | Identifies exactly which item you looked at. | |
Product title | Mouse Gamer sem Fio Attack Shark X11 | The full name of the product, sent in plain text. | |
Page URL | https://www.kabum.com.br/produto/904345 | The exact store page you were on. | |
Persistent install ID | 017-31ac09bb-efd3-f6b4-2cae-cc7c1fc59021 | A fixed identifier for your install that ties every event back together over time. | |
Extension + browser version | isxversion=6.7.0, isxbrowser=chromium | Which build of the extension and which browser you're running. |
Every request is tagged with the same persistent ID
onMessage('bg_searchProduct', (payload, sender, sendResponse) => {
// forwards payload straight to the backend
dispatch(RemoteApi.getJson, 'actions/json/product', payload, sendResponse, { ttl: TTL_MEDIUM });
});RemoteApi.buildParams = async (params = {}) => {
if (!params.localid) params.localid = await getOrCreateInstallId(); // persistent per-install ID
if (!params.isxmode) params.isxmode = 'production';
if (!params.isxversion) params.isxversion = EXT_BUILD_VERSION;
if (!params.isxbrowser) params.isxbrowser = 'chromium';
return Object.keys(params).map(k => k + '=' + encodeURIComponent(params[k])).join('&');
};- menoresprecos.dudurochatec.com.br
The extension developer's own backend. Receives product-view events and the persistent install identifier; neither is mentioned in the Chrome Web Store listing.
What it can do
Permissions this extension asks for, as declared in version 12.14.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on menoresprecos.dudurochatec.com.br
https://menoresprecos.dudurochatec.com.br/**/*
Sign you in with your Google account
identity