Is SellerSprite - Amazon Research Tool safe?
SellerSprite is medium risk. v5.0.2 adds a Creator Studio trending hook and extends interception to saved videos and a sound's video list, raising monitored API paths from 16 to 20. A real API call was intercepted live; the hook was present but not observed firing.…
Who publishes itChengdu Yunya Information Technoloy Co.,LTD - 2 other listings from the same operator, 1 of them carrying a finding
Chengdu Yunya Information Technoloy Co.,LTD - 2 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 110k+ users between them. 1 of them carries a finding.
Shared hosts - 6 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
v5.0.2 Expands TikTok Interception to New API Endpoints
v5.0.2 adds a Creator Studio trending hook and extends interception to saved videos and a sound's video list, raising monitored API paths from 16 to 20.
A real API call was intercepted live; the hook was present but not observed firing.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-200
- Source
- Dynamic sandbox
You click through to a TikTok sound's music page, browse your saved TikTok collection, or use TikTok's Creator Studio inspiration/trending tool while the extension is active.
No extension prompt or permission dialog appears, the same page-context hooks already run on every tiktok.com page load.
The v5.0.2 update adds a Creator Studio trending API hook and extends interception to two more TikTok API paths, copying their JSON responses out of the page.
We confirmed this live: browsing to a sound's music page triggered a real TikTok API call that the extension's hooked window.fetch intercepted and dispatched into the page as a musicVideoList event.
Observed during dynamic analysis: an in-page click from the TikTok home feed to a sound's music page (no full page reload) triggered this real TikTok API call, which returned a 200 response with a live itemList body (author and video engagement fields). The extension's hooked window.fetch matched the URL against the v5.0.2-expanded window.__kol_captureList, read the JSON response, and dispatched it on window as a musicVideoList CustomEvent for the content script to pick up.
- Creator Studio trending/inspiration dataTikTok endpoint /creator_studio/inspiration/trending/video, captured via a new XMLHttpRequest hook
If you use TikTok's own Creator Studio inspiration/trending tool, this new hook lets the extension read that page's response.
- Your saved ("collection") videosTikTok endpoint /api/user/collect/item_list/, captured via the existing fetch hook
The list of videos you've bookmarked to your own TikTok collection is now captured whenever you view it.
- Music/sound page video listsTikTok endpoint /api/music/item_list, captured live during dynamic analysis
The list of videos tied to a TikTok sound or music page you browse is copied, including per-video creator and engagement data.
assets/inject.ts.js, capture-list entries and XHR hook added in v5.0.2
Capture list definitions (window.__kol_captureList / _xhr)
deobfuscated/assets/inject.ts.jswindow.__kol_captureList = { "/api/recommend/item_list/": "foryouVideoList", "/api/post/item_list": "userVideoList", "/api/repost/item_list": "userRepostList", "/api/favorite/item_list": "userLikeList", "/api/collection/item_list": "userFavoriteList", "/api/user/collect/item_list/": "userPageFavoriteList", "/api/search/general/full": "searchGeneralList", "/api/search/item/full/": "searchVideoList", "/api/explore/item_list/": "exploreVideoList", "/api/challenge/item_list/": "tagVideoList", "/api/following/item_list": "followingVideoList", "/api/friends/item_list": "friendsVideoList", "/api/music/item_list": "musicVideoList", "/api/item/detail": "userVideoDetail", "/api/shop/brandy_desktop/tiktok-ug": "relatedList", "/api/shop": "shopList", "/api/user/list/": "fansList", "/api/comment/list/": "commentLsit", "/api/effect/item/list/": "effectList"};window.__kol_captureList_xhr = { "/creator_studio/inspiration/trending/video": "inspirationTrendingList"};window.__kol_captureList_urlReferer = { "/api/post/item_list": "userVideoList", "/api/comment/list/": "commentLsit", "/api/user/list/": "fansList"};XMLHttpRequest.prototype hook
deobfuscated/assets/inject.ts.jsconst c = XMLHttpRequest.prototype, w = c.open, E = c.send, h = new WeakMap; c.open = function(o, e, ...s) { try { typeof e == "string" && h.set(this, e) } catch {} return w.call(this, o, e, ...s) }, c.send = function(...o) { const e = h.get(this) || ""; let s; for (let t = 0; t < a.length; t++) { const i = a[t]; if (e.includes(i)) { s = i; break } } return s && this.addEventListener("loadend", () => { try { const t = this.responseText; if (!t) return; const i = JSON.parse(t); p(new CustomEvent(window.__kol_captureList_xhr[s], { detail: { data: i, fetchURL: e } })) } catch {} }, { once: !0 }), E.apply(this, o) };This finding covers the v5.0.2 expansion of the capture surface only. The mechanism that forwards captured TikTok data on to plugin-data.kolsprite.com is documented in a companion finding for this extension; that relay pipeline is unchanged in this version.
TikTok Feed Interception Sends Creator Data to kolsprite.com
The extension intercepts TikTok's internal API responses before the page processes them.
Dynamic analysis captured three POSTs to plugin-data.kolsprite.com seconds after the feed loaded, with creator IDs, usernames, engagement stats.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-200
- Source
- Dynamic sandbox
You navigate to tiktok.com or www.tiktok.com with the extension installed.
No further interaction is needed, interception begins as the page starts loading.
The extension sends TikTok creator profiles and video engagement data to plugin-data.kolsprite.com without a prompt.
Our dynamic analysis captured three POST requests to that endpoint during a single home-feed page load, each containing full video records with creator IDs, usernames, follower counts, and play statistics.
Three requests of this form were captured automatically on TikTok home page load during dynamic analysis. The author.id, uniqueId, video.id, and stats.playCount values are from observed traffic; remaining numeric fields are representative of the captured payload structure (illustrative).
- Content-Type
- application/json
[ { "author": { "id": "7196800649023472683", "uniqueId": "jul.spamz.fr", "secUid": "MS4wLjABAAAA-GJj7FS6deTBTBKuRGiOI4f6Wr2Yk8WLzZm1QhYr3xA", "followerCount": 42300, "heartCount": 98700 }, "id": "7608248907960814879", "stats": { "playCount": 166300000, "diggCount": 8920000, "commentCount": 127400, "shareCount": 91200 } }]- Creator numeric ID7196800649023472683
TikTok's permanent internal ID for the video creator. It can link activity across sessions and platforms.
- Creator usernamejul.spamz.fr
The creator's public TikTok handle, directly identifying a real person's account.
- Creator secUidMS4wLjABAAAA-GJj7FS6deTBTBKuRGiOI4f...
A second immutable identifier for the TikTok account used by TikTok's internal APIs.
- Follower count42300
How many followers the creator had at the time this video appeared in your feed.
- Total likes received98700
The creator's aggregate heart count across all their videos, captured at browse time.
- Video ID7608248907960814879
Unique identifier for the specific video that appeared in your feed, revealing which content you viewed.
- Video play count166300000
Global view count for the video at the time of capture, included alongside the video ID.
inject.ts.js, window.fetch override injected into TikTok's MAIN world
window.__kol_captureList = { "/api/recommend/item_list/": "foryouVideoList", "/api/post/item_list": "userVideoList", "/api/repost/item_list": "userRepostList", "/api/favorite/item_list": "userLikeList", "/api/collection/item_list": "userFavoriteList", "/api/user/collect/item_list/": "userPageFavoriteList", "/api/search/general/full": "searchGeneralList", "/api/search/item/full/": "searchVideoList", "/api/explore/item_list/": "exploreVideoList", "/api/challenge/item_list/": "tagVideoList", "/api/following/item_list": "followingVideoList", "/api/friends/item_list": "friendsVideoList", "/api/music/item_list": "musicVideoList", "/api/item/detail": "userVideoDetail", "/api/shop": "shopList"};window.__kol_captureList_xhr = { "/creator_studio/inspiration/trending/video": "inspirationTrendingList"};function y() { let l = true; const c = window.fetch; window.fetch = async function (...t) { let e = "", s; const i = t[0], n = t[1]; if (typeof i == "string") { e = i; s = n?.credentials; } else if (i instanceof URL) { e = i.href; s = n?.credentials; } else if (i instanceof Request) { e = i.url; s = i.credentials; } if (s === "omit") return c.apply(this, t); const d = Object.keys(window.__kol_captureList).find(r => e.includes(r)); if (!d) return c.apply(this, t); const o = await c.apply(this, t), m = o.clone(), L = o.headers.get("Content-Type") || ""; if (!o.ok || !L.includes("application/json")) return o; const w = await m.json(); return setTimeout(() => { const r = new URLSearchParams(e); if (r.get("post_item_list_request_type")) { const p = r.get("post_item_list_request_type"); w.tkOrder = !p || p === "0" ? "Latest" : p === "1" ? "Popular" : "Oldest"; } window.dispatchEvent(new CustomEvent(window.__kol_captureList[d], { detail: w })); if (d === "/api/post/item_list") window.dispatchEvent(new CustomEvent("urlRefererGet", { detail: e })); l = false; }, l ? 4000 : 1500), o; }; // ... XHR interception follows the same pattern ...}window.__load_kol_ss = true;setTimeout(() => { window.__load_kol_main ? document.documentElement.dataset.__load_kol_main = "true" : y();}, 1);- plugin-data.kolsprite.com
Receives POST requests with TikTok video records (creator profiles, video IDs, engagement stats) harvested from intercepted API responses. Listed in the manifest host_permissions.
- www.kolsprite.com
Primary domain of the KolSprite influencer analytics service, which is the operator of the data collection. The extension's Amazon seller tools also connect to this host.
- o.kolsprite.com
Receives audio caption upload requests (POST multipart/form-data) from the background service worker when users invoke TikTok audio transcription features.