Is Remove YouTube Shorts safe?

Medium risk

Remove YouTube Shorts is medium risk. On install/update, the service worker collects your user-agent, platform, IP, and country, hashes them, and sends the fingerprint to arktech-plugins.vercel.app, unrelated to its purpose, after a random 1-21s delay, then caches it locally.

ArkTechv2.1.7Chrome Web Store
45Risk
Who publishes it

ArkTech - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
ArkTech

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Fingerprinting Beacon Transmitted on Install

On install/update, the service worker collects your user-agent, platform, IP, and country, hashes them, and sends the fingerprint to arktech-plugins.vercel.app, unrelated to its purpose, after a random 1-21s delay, then caches it locally.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install or update Remove YouTube Shorts.

The extension did this

The extension collects your IP address, user-agent, platform, and country, hashes them into a fingerprint, and sends it to arktech-plugins.vercel.app.

The transmission happens automatically after a randomized 1-21 second delay. No prompt or UI element is shown.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://arktech-plugins.vercel.app/api/reciveInfo
Dynamic analysis captured 3 POST requests to this endpoint during dynamic analysis with reason=update replay. Body format: hash prefix (up to 30 chars) + colon-separated platform, IP, and country.
Headers
Content-Typeapplication/json
Body
{
  "UID": "-o648n0:Linux x86_64:82.3.220.102:GB"
}
03EvidenceFIELD TABLE
Data collected to derive the transmitted UID:
FieldValueWhy it matters
User-agent string
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Your browser version and operating system, e.g. 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36'.
Platform
Linux x86_64Your operating system platform reported by the browser, e.g. 'Linux x86_64'.
Public IP address
82.3.220.102Your network's public IP address, fetched from api.country.is at install time.
Country code
GBYour country derived from your IP address at install time.
04EvidenceCODE COMPARE
The code that does this

The fingerprinting and transmission logic in background.js:

What it actually does
Readable equivalent with comments
chrome.runtime.onInstalled.addListener(async (event) => {
  // Fires on both fresh install and extension update
  if (event.reason !== 'install' && event.reason !== 'update') return;

  chrome.storage.local.get('shortsRemoverUniqueUserId', async (stored) => {
    // Only runs if no UID has been persisted yet (i.e. first time)
    if (stored.shortsRemoverUniqueUserId) return;

    // Step 1: Collect device data
    const userAgent = navigator.userAgent;
    const platform  = navigator.platform;
    let ip      = 'unknown_ip';
    let country = 'unknown_country';

    try {
      // Fetch public IP + country from a third-party geolocation service
      const resp = await fetch('https://api.country.is/');
      const data = await resp.json();
      ip      = data.ip      || 'unknown_ip';
      country = data.country || 'unknown_country';
    } catch (_) {}

    // Step 2: Build fingerprint hash (djb2 variant, base-36, sliced to 30 chars)
    function djb2Hash(str) {
      let h = 0;
      for (let i = 0; i < str.length; i++) {
        h = (h << 5) - h + str.charCodeAt(i);
        h |= 0; // convert to 32-bit int
      }
      return h.toString(36);
    }

    const raw = `${userAgent}:${platform}:${ip}:${Date.now()}:${country}`;
    const uid = `${djb2Hash(raw).slice(0, 30)}:${platform}:${ip}:${country}`;
    // Example result: '-o648n0:Linux x86_64:82.3.220.102:GB'

    // Step 3: Wait a random 1–21 seconds, then POST the UID
    const delaySecs = Math.floor(21 * Math.random()) + 1;
    await new Promise(resolve => setTimeout(resolve, delaySecs * 1000));

    const body = { UID: uid };
    const res = await fetch('https://arktech-plugins.vercel.app/api/reciveInfo', {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify(body)
    });

    if (res.ok) {
      // Persist so future installs/updates don't re-transmit
      chrome.storage.local.set({ shortsRemoverUniqueUserId: uid });
    }
  });
});
05EvidenceTHIRD PARTY LIST
Destinations contacted during install:
  • api.country.is

    Geolocation lookup service; extension fetches the user's public IP and country code from this endpoint during fingerprint construction.

  • arktech-plugins.vercel.app

    Developer-controlled endpoint on Vercel's hosting platform. Receives the derived fingerprint UID via POST on first install or update.

What it can do

Permissions this extension asks for, as declared in version 2.1.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 2.1.7, which we have not unpacked yet.

  • Read and change your data on youtube.com

    *://*.youtube.com/*

  • Store data in your browser

    storage

Updated 30 September 2026mgngbgbhliflggkamjnpdmegbkidiapm