Is Softdreams công cụ ký điện tử safe?

Low risk

Softdreams công cụ ký điện tử exposes a hardware-token signing bridge to any web page without enforcing an origin allowlist.

The extension injects a script into every page that makes cryptographic signing and certificate operations available to any JavaScript on the page. Messages relayed through the content script reach a native messaging host (com.tokensign) that performs signing with the user's hardware token; the background script contains an unfilled TODO where an origin allowlist check should be but is absent. As a result, any site the user visits can trigger signing operations or read certificate details without restriction.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Softdreams JSCv0.1.6Chrome Web Store
20Risk
Who publishes it

Softdreams JSC - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Softdreams JSC

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

open-eid.github.io
Also called by 4 other listings, including VIETTEL, Asan ID token signing

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.1.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Schedule its own background tasks

    alarms

Updated 30 September 2026bkfagmnjmfjalbbaiphoiiafghlknpog