Is video downloader - CocoCut safe?

Medium risk

CocoCut captures Cookie and Authorization headers from all HTTP requests and stores them in extension session storage.

During video capture sessions, CocoCut intercepts every outgoing HTTP request via the webRequest API and extracts Cookie and Authorization headers, storing them in chrome.storage.session/local under MediaData. The extension also removes sandbox attributes from all iframes on any active page during capture, collapsing their isolation boundaries. Extension traffic endpoints are dynamically updated from a remote config at config.cococut.net, allowing the operator to redirect all extension-to-server communication to remotely-specified domains.

45Risk
Who publishes it

matc - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
matc

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

cococut.net
Also called by 2 other listings, including Video Controls Plus

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Video Downloader Sends the Page URL to Its Own Server

Clicking download on a DASH/HLS stream opens a tab to cococut.net with the video page's URL as topWebpageUrl, reflected in four follow-on referrers too.

The destination domain is remotely configurable.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the download button for a live DASH or HLS stream detected in the CocoCut popup.

The click fires the popup's '#medialist #mpd' handler, or the equivalent flow for HLS/.m3u8 streams.

The extension did this

CocoCut opens a new tab to its own processing server with the URL of the page you were watching attached.

The new tab navigates to cococut.net's download page with a topWebpageUrl query parameter set to the active tab's full URL.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://cococut.net/ahls.html?mpd_url=https%3A%2F%2Fdash.akamaized.net%2Fakamai%2Fbbb_30fps%2Fbbb_30fps.mpd&vtid=1585209823&topWebpageUrl=https%3A%2F%2Freference.dashif.org%2Fdash.js%2Flatest%2Fsamples%2Fdash-if-reference-player%2Findex.html
The landing page loaded normally. Four subresource requests it issued (logo32x32.png, pro-promotion.js, userc.js, i18n/userc.js) carried the full navigated URL, including the topWebpageUrl value, as their initiator, confirming the source page's address reached cococut.net's server rather than staying local to the browser.
03EvidenceCODE COMPARE
The code that does this

popup.js, the '#medialist #mpd' download click handler

What it actually does
$("#medialist #mpd").off().on("click", async function () {
  // Read the currently active tab (the page the user was watching the video on)
  const tabs = await chrome.tabs.query({ active: true, currentWindow: true });
  const activeTab = tabs.length > 0 ? tabs[0] : null;
  if (!activeTab) {
    $("#tempntc").html(l("t2_dlM3U8_err")).fadeIn(500).delay(1500).fadeOut(500);
    return;
  }

  const manifestUrl = $(this).parent().parent().next().find("a").attr("href");

  // Build the destination URL: domain comes from remotely-fetched config
  // (homedomain/prodomain from config.cococut.net/config.json)
  const domainSuffix = await getConfiguredDomain();
  const destination = new URL("https" + domainSuffix);

  destination.searchParams.set("mpd_url", manifestUrl);
  destination.searchParams.set("vtid", activeTab.id);
  // The source page's full URL is attached here
  destination.searchParams.set("topWebpageUrl", activeTab?.url || "");

  chrome.tabs.create({ url: destination.toString() });
});
04EvidenceFIELD TABLE
Query parameters sent to cococut.net when a download is started
FieldValueWhy it matters
The page you were on
https://reference.dashif.org/dash.js/latest/samples/dash-if-reference-player/index.htmlThe full address of the tab you were watching the video in, including its path and query string, sent as the topWebpageUrl parameter.
Video manifest address
https://dash.akamaized.net/akamai/bbb_30fps/bbb_30fps.mpdThe address of the DASH manifest or HLS playlist you're downloading, sent as mpd_url.
Browser tab identifier
1585209823An internal Chrome tab ID used to link the download page back to the tab that started it, sent as vtid.
05EvidenceTHIRD PARTY LIST
Where the page URL is sent
  • cococut.net

    CocoCut's download-processing site; receives the source page's URL as a query param each download. Read from a runtime config, so the vendor can change it without a new release.

What it can do

Permissions this extension asks for, as declared in version 3.55. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 3.83, which we have not unpacked yet.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Watch every request your browser makes

    webRequest

  • Start, monitor and manage your downloads

    downloads

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Run its own code inside the pages you visit

    scripting

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Run hidden pages in the background

    offscreen

Where it sends data

Destinations our analysis observed CocoCut contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • config.cococut.net

    CocoCut sends data to config.cococut.net. No other extension we have analysed sends data here.

  • parser-config.cocoshot.net

    CocoCut sends data to parser-config.cocoshot.net. No other extension we have analysed sends data here.

  • pro.cococut.net

    CocoCut sends data to pro.cococut.net. No other extension we have analysed sends data here.

Updated 30 September 2026ekhbcipncbkfpkaianbjbcbmfehjflpf