Is SellerSprite - Amazon Research Tool safe?

Medium risk

SellerSprite is medium risk. v5.0.2 adds a Creator Studio trending hook and extends interception to saved videos and a sound's video list, raising monitored API paths from 16 to 20. A real API call was intercepted live; the hook was present but not observed firing.…

Yunya Technologyv5.0.5Chrome Web Store
49Risk
Who publishes it

Chengdu Yunya Information Technoloy Co.,LTD - 2 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Yunya Technology
Declared legal entity
Chengdu Yunya Information Technoloy Co.,LTD
Registered address
No.200 Tianfu Street 5, Gaoxinqu, Chengu, Sichuan 610041, China
Registered contact
chen zhiwu

Same store account

2 other listings published from this account, 110k+ users between them. 1 of them carries a finding.

Shared hosts - 6 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

o.sellersprite.com
Also called by 2 other listings, including SellerSprite - The Most Professional Amazon Tool
apps.voc.ai
Also called by 4 other listings, including SellerSprite - The Most Professional Amazon Tool, Shulex Copilot:ChatGPT E-commerce Sidebar, Shulex Copilot
sellersprite.ai
Also called by 5 other listings, including SellerSprite - The Most Professional Amazon Tool, Listing Pro
voc.ai
Also called by 5 other listings, including SellerSprite - The Most Professional Amazon Tool, Shulex Copilot:ChatGPT E-commerce Sidebar, Shulex Copilot
o.kolsprite.com
Also called by 6 other listings, including TikTok Cleaner | Remove Likes & Reposts with One-Click
kolsprite.com
Also called by 8 other listings, including TikTok Cleaner | Remove Likes & Reposts with One-Click, Check Engagement Rate Instagram & Tiktok by KOL.ID

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

v5.0.2 Expands TikTok Interception to New API Endpoints

v5.0.2 adds a Creator Studio trending hook and extends interception to saved videos and a sound's video list, raising monitored API paths from 16 to 20.

A real API call was intercepted live; the hook was present but not observed firing.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-200
Source
Dynamic sandbox
What actually happens
You did this

You click through to a TikTok sound's music page, browse your saved TikTok collection, or use TikTok's Creator Studio inspiration/trending tool while the extension is active.

No extension prompt or permission dialog appears, the same page-context hooks already run on every tiktok.com page load.

The extension did this

The v5.0.2 update adds a Creator Studio trending API hook and extends interception to two more TikTok API paths, copying their JSON responses out of the page.

We confirmed this live: browsing to a sound's music page triggered a real TikTok API call that the extension's hooked window.fetch intercepted and dispatched into the page as a musicVideoList event.

Captured request
GEThttps://www.tiktok.com/api/music/item_list/

Observed during dynamic analysis: an in-page click from the TikTok home feed to a sound's music page (no full page reload) triggered this real TikTok API call, which returned a 200 response with a live itemList body (author and video engagement fields). The extension's hooked window.fetch matched the URL against the v5.0.2-expanded window.__kol_captureList, read the JSON response, and dispatched it on window as a musicVideoList CustomEvent for the content script to pick up.

TikTok data surfaces added or newly reachable in v5.0.2
  • Creator Studio trending/inspiration data
    TikTok endpoint /creator_studio/inspiration/trending/video, captured via a new XMLHttpRequest hook

    If you use TikTok's own Creator Studio inspiration/trending tool, this new hook lets the extension read that page's response.

  • Your saved ("collection") videos
    TikTok endpoint /api/user/collect/item_list/, captured via the existing fetch hook

    The list of videos you've bookmarked to your own TikTok collection is now captured whenever you view it.

  • Music/sound page video lists
    TikTok endpoint /api/music/item_list, captured live during dynamic analysis

    The list of videos tied to a TikTok sound or music page you browse is copied, including per-video creator and engagement data.

The code that does this

assets/inject.ts.js, capture-list entries and XHR hook added in v5.0.2

Readable version

Capture list definitions (window.__kol_captureList / _xhr)

deobfuscated/assets/inject.ts.js
window.__kol_captureList = {  "/api/recommend/item_list/": "foryouVideoList",  "/api/post/item_list": "userVideoList",  "/api/repost/item_list": "userRepostList",  "/api/favorite/item_list": "userLikeList",  "/api/collection/item_list": "userFavoriteList",  "/api/user/collect/item_list/": "userPageFavoriteList",  "/api/search/general/full": "searchGeneralList",  "/api/search/item/full/": "searchVideoList",  "/api/explore/item_list/": "exploreVideoList",  "/api/challenge/item_list/": "tagVideoList",  "/api/following/item_list": "followingVideoList",  "/api/friends/item_list": "friendsVideoList",  "/api/music/item_list": "musicVideoList",  "/api/item/detail": "userVideoDetail",  "/api/shop/brandy_desktop/tiktok-ug": "relatedList",  "/api/shop": "shopList",  "/api/user/list/": "fansList",  "/api/comment/list/": "commentLsit",  "/api/effect/item/list/": "effectList"};window.__kol_captureList_xhr = {  "/creator_studio/inspiration/trending/video": "inspirationTrendingList"};window.__kol_captureList_urlReferer = {  "/api/post/item_list": "userVideoList",  "/api/comment/list/": "commentLsit",  "/api/user/list/": "fansList"};

XMLHttpRequest.prototype hook

deobfuscated/assets/inject.ts.js
const c = XMLHttpRequest.prototype,    w = c.open,    E = c.send,    h = new WeakMap;  c.open = function(o, e, ...s) {    try {      typeof e == "string" && h.set(this, e)    } catch {}    return w.call(this, o, e, ...s)  }, c.send = function(...o) {    const e = h.get(this) || "";    let s;    for (let t = 0; t < a.length; t++) {      const i = a[t];      if (e.includes(i)) {        s = i;        break      }    }    return s && this.addEventListener("loadend", () => {      try {        const t = this.responseText;        if (!t) return;        const i = JSON.parse(t);        p(new CustomEvent(window.__kol_captureList_xhr[s], {          detail: {            data: i,            fetchURL: e          }        }))      } catch {}    }, {      once: !0    }), E.apply(this, o)  };
Observation

This finding covers the v5.0.2 expansion of the capture surface only. The mechanism that forwards captured TikTok data on to plugin-data.kolsprite.com is documented in a companion finding for this extension; that relay pipeline is unchanged in this version.

TikTok Feed Interception Sends Creator Data to kolsprite.com

The extension intercepts TikTok's internal API responses before the page processes them.

Dynamic analysis captured three POSTs to plugin-data.kolsprite.com seconds after the feed loaded, with creator IDs, usernames, engagement stats.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-200
Source
Dynamic sandbox
What actually happens
You did this

You navigate to tiktok.com or www.tiktok.com with the extension installed.

No further interaction is needed, interception begins as the page starts loading.

The extension did this

The extension sends TikTok creator profiles and video engagement data to plugin-data.kolsprite.com without a prompt.

Our dynamic analysis captured three POST requests to that endpoint during a single home-feed page load, each containing full video records with creator IDs, usernames, follower counts, and play statistics.

Captured request
POSThttps://plugin-data.kolsprite.com/v1/plugin/video/label/add

Three requests of this form were captured automatically on TikTok home page load during dynamic analysis. The author.id, uniqueId, video.id, and stats.playCount values are from observed traffic; remaining numeric fields are representative of the captured payload structure (illustrative).

Headers
Content-Type
application/json
Body
[  {    "author": {      "id": "7196800649023472683",      "uniqueId": "jul.spamz.fr",      "secUid": "MS4wLjABAAAA-GJj7FS6deTBTBKuRGiOI4f6Wr2Yk8WLzZm1QhYr3xA",      "followerCount": 42300,      "heartCount": 98700    },    "id": "7608248907960814879",    "stats": {      "playCount": 166300000,      "diggCount": 8920000,      "commentCount": 127400,      "shareCount": 91200    }  }]
Creator and video fields observed in POST body
  • Creator numeric ID
    7196800649023472683

    TikTok's permanent internal ID for the video creator. It can link activity across sessions and platforms.

  • Creator username
    jul.spamz.fr

    The creator's public TikTok handle, directly identifying a real person's account.

  • Creator secUid
    MS4wLjABAAAA-GJj7FS6deTBTBKuRGiOI4f...

    A second immutable identifier for the TikTok account used by TikTok's internal APIs.

  • Follower count
    42300

    How many followers the creator had at the time this video appeared in your feed.

  • Total likes received
    98700

    The creator's aggregate heart count across all their videos, captured at browse time.

  • Video ID
    7608248907960814879

    Unique identifier for the specific video that appeared in your feed, revealing which content you viewed.

  • Video play count
    166300000

    Global view count for the video at the time of capture, included alongside the video ID.

The code that does this

inject.ts.js, window.fetch override injected into TikTok's MAIN world

Readable version
window.__kol_captureList = {  "/api/recommend/item_list/": "foryouVideoList",  "/api/post/item_list": "userVideoList",  "/api/repost/item_list": "userRepostList",  "/api/favorite/item_list": "userLikeList",  "/api/collection/item_list": "userFavoriteList",  "/api/user/collect/item_list/": "userPageFavoriteList",  "/api/search/general/full": "searchGeneralList",  "/api/search/item/full/": "searchVideoList",  "/api/explore/item_list/": "exploreVideoList",  "/api/challenge/item_list/": "tagVideoList",  "/api/following/item_list": "followingVideoList",  "/api/friends/item_list": "friendsVideoList",  "/api/music/item_list": "musicVideoList",  "/api/item/detail": "userVideoDetail",  "/api/shop": "shopList"};window.__kol_captureList_xhr = {  "/creator_studio/inspiration/trending/video": "inspirationTrendingList"};function y() {  let l = true;  const c = window.fetch;  window.fetch = async function (...t) {    let e = "", s;    const i = t[0], n = t[1];    if (typeof i == "string") {      e = i;      s = n?.credentials;    } else if (i instanceof URL) {      e = i.href;      s = n?.credentials;    } else if (i instanceof Request) {      e = i.url;      s = i.credentials;    }    if (s === "omit") return c.apply(this, t);    const d = Object.keys(window.__kol_captureList).find(r => e.includes(r));    if (!d) return c.apply(this, t);    const o = await c.apply(this, t),      m = o.clone(),      L = o.headers.get("Content-Type") || "";    if (!o.ok || !L.includes("application/json")) return o;    const w = await m.json();    return setTimeout(() => {      const r = new URLSearchParams(e);      if (r.get("post_item_list_request_type")) {        const p = r.get("post_item_list_request_type");        w.tkOrder = !p || p === "0" ? "Latest" : p === "1" ? "Popular" : "Oldest";      }      window.dispatchEvent(new CustomEvent(window.__kol_captureList[d], { detail: w }));      if (d === "/api/post/item_list")        window.dispatchEvent(new CustomEvent("urlRefererGet", { detail: e }));      l = false;    }, l ? 4000 : 1500), o;  };  // ... XHR interception follows the same pattern ...}window.__load_kol_ss = true;setTimeout(() => {  window.__load_kol_main    ? document.documentElement.dataset.__load_kol_main = "true"    : y();}, 1);
Destinations receiving TikTok data
    • plugin-data.kolsprite.com

    Receives POST requests with TikTok video records (creator profiles, video IDs, engagement stats) harvested from intercepted API responses. Listed in the manifest host_permissions.

    • www.kolsprite.com

    Primary domain of the KolSprite influencer analytics service, which is the operator of the data collection. The extension's Amazon seller tools also connect to this host.

    • o.kolsprite.com

    Receives audio caption upload requests (POST multipart/form-data) from the background service worker when users invoke TikTok audio transcription features.

Updated 30 September 2026lnbmbgocenenhhhdojdielgnmeflbnfb