Star - Gists · GitHub

Video Downloader professional kmdldgcmokdpmacblnehppgkjphcbpnn background.js

This is the source of background.js for a now-unpublished Chrome extension called "Video Downloader professional" (ID kmdldgcmokdpmacblnehppgkjphcbpnn, since then replaced with another "Video Downloader professional" (ID bacakpdjpomjaelpkpkabmedhkoongbi). This script is republished here for educational / research purposes. It has initially been extracted from the extension’s archive available as v2.4 on https://www.crx4chrome.com/.

Why is this interesting?

The extension has appeared in malware discussions in the past. Its replacement of Video downloader professional "bacakpdjpomjaelpkpkabmedhkoongbi" seems related to the ownership change of The Great Suspender.

What does the code do?

It’s unclear to me, but I hope you can figure it out!

The "background processing" code from line 2 to line 654, appears unrelated to the video download features. This code appears to periodically phone home to a configuration server, and from there contains additional logic to make subsequent background requests / open new tabs as instructed.

Từ khóa » Video Downloader Professional This Extension Contains Malware