Discord Get User Token
accgjfooejbpdchkfpngkjjdekkcbnfd
Risk Score
5.15
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension explicitly designed to steal Discord auth tokens — stated primary function is credential extraction.
- Brand impersonation: uses 'Discord' in name without ownership, gmail dev, no verified publisher.
- Privacy policy is generic Google account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
- Content script on all discord.com pages enables full session token access for 30K users.
- Free-webmail developer with no business identity; high-capability tool with low accountability.
Evidence
- stated_function_credential_theft store Description explicitly states: 'streamlines the process of obtaining an Authorization Token for a logged-in Discord user'.
- brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; uses Discord brand without authorization.
- free_webmail_developer manifest developer_email=pirtpalmatharu@gmail.com; no business domain; no verified publisher badge.
- generic_google_privacy_policy store Privacy policy is myaccount.google.com policy: scope_extension=false, data_collection=true, third_party_sharing=true.
- content_script_discord manifest content_scripts_matches=[https://discord.com/*]; enables DOM access to read session tokens.
- no_csp crx content_security_policy=null; MV3 default applies but no explicit policy declared.
- rating_below_4 store Rating 3.7; below trust threshold, consistent with risk profile.
- is_featured_by_google store is_featured_by_google=true; partially offsets reputation concern but does not excuse function.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- clipboardWrite medium Can inject content into user clipboard; used to copy token.
- host_permission: https://discord.com/* high Content-script access to all Discord pages; can read auth tokens from DOM.
Pillar Scores
Permissions4.50
Reputation8.50
Network0.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
033da2e6c9d6…
Force block
— not fired
Score recovered
no
Elapsed
19.2s