Is UAR_SKT safe?
UAR_SKT captures the full page DOM on every navigation and forwards matching URLs to a locally installed SKT corporate management application via native messaging.
On every completed navigation across all sites, the extension captures the full DOM HTML of the current page and checks it for an SKT corporate deny-page marker. If the marker is present, or if the visited URL matches a hardcoded blocklist of webmail and collaboration services, the browsed URL is sent to the native host 'com.skt.uar' installed on the local machine. Matching URLs are also redirected to an SKT corporate block page at mydesk.sktelecom.com.
Who publishes itCISOLUTIONS - 2 other listings from the same operator, 1 of them carrying a finding
CISOLUTIONS - 2 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 381 users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Visits to webmail and meeting sites redirect to an SK Telecom deny page
The extension checks every page you visit against six hardcoded hostnames, including webmail and Webex Meetings, and force-navigates the tab to an SK Telecom deny page on a match.
We observed this fire 7ms after visiting mailplug.com.
You open a tab to a workplace webmail, helpdesk, or meeting site.
This covers ordinary browsing to any of the six hardcoded hostnames and IPs, not just an SKT-run destination.
The extension immediately forces the tab to an SK Telecom corporate deny page instead of the site you asked for.
We observed the tab land on mydesk.sktelecom.com/Internet_deny.html 7ms after visiting mailplug.com, and again via a redirect chain after visiting meetings.webex.com.
| Field | Value | Why it matters | |
|---|---|---|---|
Korean trade-association webmail | webmail.ktoa.or.kr | Opening this organization's webmail is blocked and redirected before it loads. | |
Business web portal | muplus.co.kr | Matched the same way as the other hardcoded hosts, by substring, anywhere in the URL. | |
Business email provider | mailplug.com | A workplace email service; opening it here interrupts you reading your own mail. | |
Vendor support / helpdesk portal | custhelp.com | A third-party customer-support domain used by many companies, blocked outright. | |
A hardcoded IP address | 116.125.29.54 | Matched by raw IP, so anything hosted at that address is blocked regardless of hostname. | |
Cisco Webex Meetings | meetings.webex.com | Joining or starting a video meeting through this link is blocked instead of connecting. |
The unfiltered navigation listener and the hardcoded blocklist check
var redirectpage = 'http://mydesk.sktelecom.com/Internet_deny.html'; // the deny page
var includeurl = 'chrome://'; // only chrome:// pages and the deny page itself are exempt
function SendURL_BeforeNavigate(details) {
// Runs on every navigation in every tab; no addListener filter object was passed.
if ((details.url == redirectpage) || (details.url == 'about:blank') || (details.url.includes(includeurl))) {
return; // only these are ever skipped
}
compareURL(details.url); // sets the module-level `compareresult` flag
if (compareresult) {
chrome.tabs.update({ url: redirectpage }); // rewrite the tab before the real page loads
connect(); // open a native-messaging port
sendNativeMessage(details.url); // relay the visited URL (covered by a separate claim)
}
}
// No filter object, e.g. {url: [{hostContains: ...}]}, is passed here, so Chrome
// invokes this listener for every navigation the browser makes.
chrome.webNavigation.onBeforeNavigate.addListener(SendURL_BeforeNavigate);function compareURL(currentURL) {
// A commented-out branch would have fetched this list from a remote .ini file;
// it is dead code. The list actually used is hardcoded below.
var inidata = "[Setting]\r1=webmail.ktoa.or.kr\r2=muplus.co.kr\r3=mailplug.com\r4=custhelp.com\r5=116.125.29.54\r6=meetings.webex.com";
var urllist = parseINIString(inidata);
var objURL = Object.values(urllist);
var arrURL = Object.values(objURL[0]); // ["webmail.ktoa.or.kr", "muplus.co.kr", "mailplug.com", "custhelp.com", "116.125.29.54", "meetings.webex.com"]
compareresult = false;
for (var index = 0; index < arrURL.length; ++index) {
// Substring match anywhere in the URL, not an exact hostname comparison.
if (currentURL.includes(arrURL[index])) {
compareresult = true;
}
}
}What it can do
Permissions this extension asks for, as declared in version 1.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
See every page you navigate to, as you navigate to it
webNavigation
See the address and title of every tab you have open
tabs
Where it sends data
Destinations our analysis observed UAR_SKT contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- mydesk.sktelecom.com
UAR_SKT sends data to mydesk.sktelecom.com. No other extension we have analysed sends data here.
- com.skt.uar (local native application)
UAR_SKT sends data to com.skt.uar (local native application). Named as a recipient in this extension's own analysis.