Is UAR_SKT safe?

Medium risk

UAR_SKT captures the full page DOM on every navigation and forwards matching URLs to a locally installed SKT corporate management application via native messaging.

On every completed navigation across all sites, the extension captures the full DOM HTML of the current page and checks it for an SKT corporate deny-page marker. If the marker is present, or if the visited URL matches a hardcoded blocklist of webmail and collaboration services, the browsed URL is sent to the native host 'com.skt.uar' installed on the local machine. Matching URLs are also redirected to an SKT corporate block page at mydesk.sktelecom.com.

CISOLUTIONSv1.4Chrome Web Store
45Risk
Who publishes it

CISOLUTIONS - 2 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
CISOLUTIONS

Same store account

2 other listings published from this account, 381 users between them. 1 of them carries a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Visits to webmail and meeting sites redirect to an SK Telecom deny page

The extension checks every page you visit against six hardcoded hostnames, including webmail and Webex Meetings, and force-navigates the tab to an SK Telecom deny page on a match.

We observed this fire 7ms after visiting mailplug.com.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open a tab to a workplace webmail, helpdesk, or meeting site.

This covers ordinary browsing to any of the six hardcoded hostnames and IPs, not just an SKT-run destination.

The extension did this

The extension immediately forces the tab to an SK Telecom corporate deny page instead of the site you asked for.

We observed the tab land on mydesk.sktelecom.com/Internet_deny.html 7ms after visiting mailplug.com, and again via a redirect chain after visiting meetings.webex.com.

02EvidenceFIELD TABLE
The hardcoded blocklist checked on every page load
FieldValueWhy it matters
Korean trade-association webmail
webmail.ktoa.or.krOpening this organization's webmail is blocked and redirected before it loads.
Business web portal
muplus.co.krMatched the same way as the other hardcoded hosts, by substring, anywhere in the URL.
Business email provider
mailplug.comA workplace email service; opening it here interrupts you reading your own mail.
Vendor support / helpdesk portal
custhelp.comA third-party customer-support domain used by many companies, blocked outright.
A hardcoded IP address
116.125.29.54Matched by raw IP, so anything hosted at that address is blocked regardless of hostname.
Cisco Webex Meetings
meetings.webex.comJoining or starting a video meeting through this link is blocked instead of connecting.
03EvidenceNETWORK CAPTURE
Captured request
GEThttp://mydesk.sktelecom.com/Internet_deny.html
Tab forced to this URL 7ms after navigating to https://www.mailplug.com/. A second, independent visit to https://meetings.webex.com/ produced a 302 redirect chain that also landed on this page before continuing to the SK Telecom corporate portal login.
04EvidenceCODE COMPARE
The code that does this

The unfiltered navigation listener and the hardcoded blocklist check

What it actually does
Annotated: the listener has no URL filter and fires unconditionallybackground.js
var redirectpage = 'http://mydesk.sktelecom.com/Internet_deny.html'; // the deny page
var includeurl = 'chrome://'; // only chrome:// pages and the deny page itself are exempt

function SendURL_BeforeNavigate(details) {
  // Runs on every navigation in every tab; no addListener filter object was passed.
  if ((details.url == redirectpage) || (details.url == 'about:blank') || (details.url.includes(includeurl))) {
    return; // only these are ever skipped
  }

  compareURL(details.url); // sets the module-level `compareresult` flag
  if (compareresult) {
    chrome.tabs.update({ url: redirectpage }); // rewrite the tab before the real page loads
    connect();                                  // open a native-messaging port
    sendNativeMessage(details.url);              // relay the visited URL (covered by a separate claim)
  }
}

// No filter object, e.g. {url: [{hostContains: ...}]}, is passed here, so Chrome
// invokes this listener for every navigation the browser makes.
chrome.webNavigation.onBeforeNavigate.addListener(SendURL_BeforeNavigate);
Annotated: the hardcoded blocklist (dead remote-fetch path never runs)background.js
function compareURL(currentURL) {
  // A commented-out branch would have fetched this list from a remote .ini file;
  // it is dead code. The list actually used is hardcoded below.
  var inidata = "[Setting]\r1=webmail.ktoa.or.kr\r2=muplus.co.kr\r3=mailplug.com\r4=custhelp.com\r5=116.125.29.54\r6=meetings.webex.com";

  var urllist = parseINIString(inidata);
  var objURL = Object.values(urllist);
  var arrURL = Object.values(objURL[0]); // ["webmail.ktoa.or.kr", "muplus.co.kr", "mailplug.com", "custhelp.com", "116.125.29.54", "meetings.webex.com"]

  compareresult = false;
  for (var index = 0; index < arrURL.length; ++index) {
    // Substring match anywhere in the URL, not an exact hostname comparison.
    if (currentURL.includes(arrURL[index])) {
      compareresult = true;
    }
  }
}

What it can do

Permissions this extension asks for, as declared in version 1.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See every page you navigate to, as you navigate to it

    webNavigation

  • See the address and title of every tab you have open

    tabs

Where it sends data

Destinations our analysis observed UAR_SKT contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • mydesk.sktelecom.com

    UAR_SKT sends data to mydesk.sktelecom.com. No other extension we have analysed sends data here.

  • com.skt.uar (local native application)

    UAR_SKT sends data to com.skt.uar (local native application). Named as a recipient in this extension's own analysis.

Updated 30 September 2026fiejnpolkeifcohdoehpckibdhgjalgo