Is video downloader - CocoCut safe?
CocoCut captures Cookie and Authorization headers from all HTTP requests and stores them in extension session storage.
During video capture sessions, CocoCut intercepts every outgoing HTTP request via the webRequest API and extracts Cookie and Authorization headers, storing them in chrome.storage.session/local under MediaData. The extension also removes sandbox attributes from all iframes on any active page during capture, collapsing their isolation boundaries. Extension traffic endpoints are dynamically updated from a remote config at config.cococut.net, allowing the operator to redirect all extension-to-server communication to remotely-specified domains.
Who publishes itmatc - no other listings under this identity, 1 shared hostname
matc - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Video Downloader Sends the Page URL to Its Own Server
Clicking download on a DASH/HLS stream opens a tab to cococut.net with the video page's URL as topWebpageUrl, reflected in four follow-on referrers too.
The destination domain is remotely configurable.
You click the download button for a live DASH or HLS stream detected in the CocoCut popup.
The click fires the popup's '#medialist #mpd' handler, or the equivalent flow for HLS/.m3u8 streams.
CocoCut opens a new tab to its own processing server with the URL of the page you were watching attached.
The new tab navigates to cococut.net's download page with a topWebpageUrl query parameter set to the active tab's full URL.
popup.js, the '#medialist #mpd' download click handler
$("#medialist #mpd").off().on("click", async function () {
// Read the currently active tab (the page the user was watching the video on)
const tabs = await chrome.tabs.query({ active: true, currentWindow: true });
const activeTab = tabs.length > 0 ? tabs[0] : null;
if (!activeTab) {
$("#tempntc").html(l("t2_dlM3U8_err")).fadeIn(500).delay(1500).fadeOut(500);
return;
}
const manifestUrl = $(this).parent().parent().next().find("a").attr("href");
// Build the destination URL: domain comes from remotely-fetched config
// (homedomain/prodomain from config.cococut.net/config.json)
const domainSuffix = await getConfiguredDomain();
const destination = new URL("https" + domainSuffix);
destination.searchParams.set("mpd_url", manifestUrl);
destination.searchParams.set("vtid", activeTab.id);
// The source page's full URL is attached here
destination.searchParams.set("topWebpageUrl", activeTab?.url || "");
chrome.tabs.create({ url: destination.toString() });
});| Field | Value | Why it matters | |
|---|---|---|---|
The page you were on | https://reference.dashif.org/dash.js/latest/samples/dash-if-reference-player/index.html | The full address of the tab you were watching the video in, including its path and query string, sent as the topWebpageUrl parameter. | |
Video manifest address | https://dash.akamaized.net/akamai/bbb_30fps/bbb_30fps.mpd | The address of the DASH manifest or HLS playlist you're downloading, sent as mpd_url. | |
Browser tab identifier | 1585209823 | An internal Chrome tab ID used to link the download page back to the tab that started it, sent as vtid. |
- cococut.net
CocoCut's download-processing site; receives the source page's URL as a query param each download. Read from a runtime config, so the vendor can change it without a new release.
What it can do
Permissions this extension asks for, as declared in version 3.55. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 3.83, which we have not unpacked yet.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
See the address and title of every tab you have open
tabs
Watch every request your browser makes
webRequest
Start, monitor and manage your downloads
downloads
Store data in your browser
storage
Schedule its own background tasks
alarms
Block and redirect the requests your browser makes
declarativeNetRequest
Run its own code inside the pages you visit
scripting
See every page you navigate to, as you navigate to it
webNavigation
Run hidden pages in the background
offscreen
Where it sends data
Destinations our analysis observed CocoCut contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- config.cococut.net
CocoCut sends data to config.cococut.net. No other extension we have analysed sends data here.
- parser-config.cocoshot.net
CocoCut sends data to parser-config.cocoshot.net. No other extension we have analysed sends data here.
- pro.cococut.net
CocoCut sends data to pro.cococut.net. No other extension we have analysed sends data here.