Is SuperNova SWF Enabler safe?

High risk

SuperNova SWF Enabler is high risk. We observed the background worker auto-request fun.getsupernova.com within seconds of starting, resolving country for ad targeting, undisclosed in the Store listing. A redirect hit Chrome's limit, but IP exposure happens at connection time.…

Tactics Technology LLCv0.93Chrome Web Store
75Risk
Who publishes it

Tactics Technology LLC - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Tactics Technology LLC
Declared legal entity
Tactics Technology LLC
Registered address
1512 US HIGHWAY 395 N, STE 7D, GARDNERVILLE, NV 89410, US

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

sans.org
Also called by 4 other listings, including Ruffle, ruffle_rs

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Automatic Startup Request Discloses Your IP to getsupernova.com

We observed the background worker auto-request fun.getsupernova.com within seconds of starting, resolving country for ad targeting, undisclosed in the Store listing.

A redirect hit Chrome's limit, but IP exposure happens at connection time.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You start Chrome with the extension installed, or the extension's background service worker wakes up from idle.

No click, search, or other interaction with the extension is required.

The extension did this

The extension automatically sends a network request to a getsupernova.com server before you do anything else.

The request is meant to resolve your country for ad and offer targeting, and reaching the server necessarily discloses your IP address to it.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://fun.getsupernova.com/fbrcguukCoskepBvNjiupwfkdlxyydgxngyqmehvc
Observed during dynamic analysis: 22 automatic GET requests to this endpoint fired immediately after the service worker started, before any interaction with the extension. The server returned an HTTP redirect; the browser's automatic redirect handling looped until it hit Chrome's redirect limit and the request ultimately errored on the client side. The IP exposure at the network connection layer had already occurred by the time that client-side error surfaced.
03EvidenceCODE COMPARE
The code that does this

The startup chain that sends the request, and what it does in plain terms

What it actually does
What this chain does
// Runs on every service-worker startup — no click, search, or other
// interaction with the extension is required.
chrome.runtime.getPlatformInfo(function () {
  saveStaticOffers(); // unconditional
});

async function saveStaticOffers() {
  const country = await getCountry(); // sends the network request below
  // ...store ad/offer data keyed by poolid + country...
}

async function getCountry() {
  // Reaching this host discloses the requester's IP address to it,
  // regardless of whether the response body can later be parsed.
  return fetch("https://fun.getsupernova.com/fbrcguukCoskepBvNjiupwfkdlxyydgxngyqmehvc");
}
04EvidenceTHIRD PARTY LIST
Where the automatic startup request lands
  • fun.getsupernova.com

    Receives an automatic startup request meant to resolve the requester's country by IP. Every startup discloses the user's IP to this host, regardless of whether the lookup succeeds.

  • getsupernova.com

    The same vendor's primary API host; receives install events, gamer-status checks, and ad/offer pool assignment requests from the same background service worker.

05EvidencePLAIN NOTE
What we did and didn't observe

The Chrome Web Store listing for SuperNova SWF Enabler does not mention country resolution, IP-based geolocation, or ad/offer personalization. The captured requests received an HTTP redirect response; because Chrome's automatic redirect-following hit the browser's redirect limit, the underlying fetch() call ultimately errored on the client side and no response body was ever delivered back to getCountry(). That downstream error does not undo the request already reaching fun.getsupernova.com's server — the IP exposure completes at the network connection layer, independent of whether a usable response is later parsed.

What it can do

Permissions this extension asks for, as declared in version 0.93. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on getsupernova.com

    https://*.getsupernova.com/

  • Store data in your browser

    storage

  • Act on the current tab, but only after you click the extension

    activeTab

  • See the address and title of every tab you have open

    tabs

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Run hidden pages in the background

    offscreen

Updated 30 September 2026mhmphnocemakkjdampibehejoaleebpo