{
  "title": "SIH current-specimen static corroboration",
  "review_date_utc": "2026-10-11",
  "mode": "Read-only source analysis; extension not installed, executed or connected to task/auth/session endpoints.",
  "acquisition": {
    "url": "https://clients2.google.com/service/update2/crx?response=redirect&prodversion=140.0.0.0&acceptformat=crx2%2Ccrx3&x=id%3Dcmeakgjggjdlcpncigglobpjbkabhmjl%26uc",
    "final_url": "https://clients2.googleusercontent.com/crx/blobs/AZPVhcRaVAs5yNYhDNwiAl4qAxTCCbPjDefB7rebGvgNN-2TUHRPcfMuycwglFVO-YurPedaR-4BVlwGZIfuoLXab8XOO301OmZQ7eal4TvHdjC2cbZq7Z-JCfqJCLy3rNpdAMZSmuVUi6O1lbV9aIeM3oIy6CkBQMiujA/CMEAKGJGGJDLCPNCIGGLOBPJBKABHMJL_2_12_1_0.crx",
    "status": 200,
    "content_type": "application/x-chrome-extension",
    "bytes": 72297305,
    "sha256": "950791bc18cfbc71e883e365078cd6e6094468c2d15aafcd1fd12413f2d289ea",
    "retrieved_at": "2026-10-11T03:32:42.840611+00:00",
    "version": "2.12.1",
    "extension_id": "cmeakgjggjdlcpncigglobpjbkabhmjl",
    "temporary_specimen": "/tmp/csgofast-static-audit/sih.crx",
    "archived_full_package": false,
    "archive_note": "72,297,305 bytes exceeds 25 MB research-copy threshold; acquisition metadata, verified signatures and bounded inert excerpts retained.",
    "prior_zip_download": {
      "url": "https://download.steaminventoryhelper.com/chrome-extension.zip",
      "result": "HTTP 403 / Cloudflare 1010; no package bytes received; stopped."
    }
  },
  "prior_specimen": {
    "version": "2.11.12",
    "zip_sha256": "63755fe96c0a55826d45661f8aec56a0b173a833ddf0e64074fd5a798425bd6a",
    "status": "Prior project audit and newly supplied report; original bytes unavailable in restored workspace.",
    "record": "../../dist/assets/evidence/extension-audit-2026-10-10/audit-record.json"
  },
  "manifest": {
    "version": "2.12.1",
    "sha256": "2c96e6f9a2d679bf76dd888265dc355d9b4862c1f24f1f71c7da182d1809194c",
    "permissions": [
      "notifications",
      "alarms",
      "storage",
      "unlimitedStorage",
      "background",
      "webRequest",
      "declarativeNetRequest",
      "declarativeNetRequestFeedback",
      "cookies",
      "activeTab",
      "management"
    ],
    "host_permissions": [
      "<all_urls>"
    ]
  },
  "location_convention": "Zero-based byte offsets in unmodified acquired files. Excerpt end offset is exclusive; lines one-based.",
  "limitations": [
    "No dynamic connection, active-client count, traffic rate, server authorization or malicious-use observation.",
    "New 2.12.1 offsets are not 2.11.12 webcrack line references.",
    "The supplied report is evidence of author analysis, not independent verification of all conclusions.",
    "No code found in the bounded review supports an arbitrary-target flood command.",
    "No review-payment mechanism found in the bounded code search; user says review audit will follow."
  ],
  "locations": [
    {
      "id": "SC01",
      "title": "Registered worker loads the background bundles",
      "file": "service-worker.js",
      "file_sha256": "03bc8f4d0ab34af3d93c0245ebb58a680b06443348473ea36d87cb975a48b64c",
      "anchor": "importScripts",
      "anchor_byte_zero_based": 393,
      "original_line_one_based": 11,
      "excerpt_start_byte_zero_based": 393,
      "excerpt_end_byte_exclusive": 532,
      "note": "",
      "reading": "The registered service worker loads the inspected background bundles; these are part of the extension’s executable background path."
    },
    {
      "id": "SC02",
      "title": "WSS provider and named setting",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "wss://wss-new.steaminventoryhelper.com",
      "anchor_byte_zero_based": 1213154,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1213004,
      "excerpt_end_byte_exclusive": 1213472,
      "note": "Connection heartbeat and runner are client capabilities, not observed live traffic.",
      "reading": "The client registers the WebSocket transport and a setting governing market-controller behavior."
    },
    {
      "id": "SC03",
      "title": "Agent checks a local switch and Steam authorization",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "e[this.settingName]&&r",
      "anchor_byte_zero_based": 513761,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 513451,
      "excerpt_end_byte_exclusive": 513783,
      "note": "",
      "reading": "The runner checks both the local controller setting and Steam authorization before taking the reviewed path."
    },
    {
      "id": "SC04",
      "title": "Default local controller switch is false",
      "file": "bundle/js/common.js",
      "file_sha256": "c7f12e778d48dffc105ab3a784b35b4d49967c38d4f1646e405d04126781a976",
      "anchor": "sih_app_market_toggle:!1",
      "anchor_byte_zero_based": 213540,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 213540,
      "excerpt_end_byte_exclusive": 213564,
      "note": "",
      "reading": "The default configuration disables the local market-controller switch. Enabled clients, rather than every installation, define the relevant population."
    },
    {
      "id": "SC05",
      "title": "Server ping stores cohort, switch and cadence",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "AVAILABLE_CONTROLLER_LAST_NUMBER_IDS:h.controllerIds",
      "anchor_byte_zero_based": 465316,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 465136,
      "excerpt_end_byte_exclusive": 465768,
      "note": "",
      "reading": "The server response can supply the controller switch, account-suffix cohort and request cadence."
    },
    {
      "id": "SC06",
      "title": "Cohort and order controller gates",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "h=f.AVAILABLE_CONTROLLER_LAST_NUMBER_IDS,p=l&&l.steamId",
      "anchor_byte_zero_based": 1224975,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1224975,
      "excerpt_end_byte_exclusive": 1225810,
      "note": "Last-digit membership is not measured fleet size. Pending-order branches can also enable the controller.",
      "reading": "Eligibility combines server-selected account suffixes with order-related branches. The operator’s configuration shapes the participating client population."
    },
    {
      "id": "SC07",
      "title": "Finite market task vocabulary",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "rv=\"trader_tool.steam.get_my_listings\"",
      "anchor_byte_zero_based": 531463,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 531463,
      "excerpt_end_byte_exclusive": 532086,
      "note": "",
      "reading": "The market controller declares nine named task types covering the reviewed market operations."
    },
    {
      "id": "SC08",
      "title": "Task dispatcher selects hardcoded handlers",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "Task.new handler: called",
      "anchor_byte_zero_based": 1131800,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1131800,
      "excerpt_end_byte_exclusive": 1132774,
      "note": "This reviewed dispatcher is not an arbitrary-URL or arbitrary-code execution command.",
      "reading": "The dispatcher maps a received task type to a fixed handler in the shipped bundle."
    },
    {
      "id": "SC09",
      "title": "Authenticated listing removal and result",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "TraderTool removeListing: called",
      "anchor_byte_zero_based": 878381,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 878381,
      "excerpt_end_byte_exclusive": 878803,
      "note": "",
      "reading": "A handler can remove a market listing through an authenticated Steam request and return the result."
    },
    {
      "id": "SC10",
      "title": "Price lookup uses a fixed Steam endpoint",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "url:\"https://steamcommunity.com/market/priceoverview/",
      "anchor_byte_zero_based": 1045007,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1045007,
      "excerpt_end_byte_exclusive": 1045190,
      "note": "",
      "reading": "The price handler builds a request to a fixed Steam market endpoint."
    },
    {
      "id": "SC11",
      "title": "Batch pricing stops when rate-limited",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "\"STEAM_RATE_LIMITED\"!==(h=g_(t.t0)).code",
      "anchor_byte_zero_based": 1061142,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1061142,
      "excerpt_end_byte_exclusive": 1061462,
      "note": "",
      "reading": "Batch price handling detects a rate-limit response and stops that batch. The requests remain subject to Steam’s controls."
    },
    {
      "id": "SC12",
      "title": "Trade send uses Steam request credentials",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "url:\"https://steamcommunity.com/tradeoffer/new/send\",headers",
      "anchor_byte_zero_based": 1200176,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1200176,
      "excerpt_end_byte_exclusive": 1200676,
      "note": "",
      "reading": "The trade-send path uses session-associated request credentials for the Steam trade endpoint."
    },
    {
      "id": "SC13",
      "title": "Permission request starts unaccepted",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "i=e.data.permission,a=e.data.project.name",
      "anchor_byte_zero_based": 938100,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 938100,
      "excerpt_end_byte_exclusive": 938991,
      "note": "This branch stores pending permission and opens the popup. This does not establish server enforcement of permissions for every command.",
      "reading": "A permission-request record begins with acceptance set to false, and the client opens the permission interface."
    },
    {
      "id": "SC14",
      "title": "Dynamic cookie-header rule",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "requestHeaders:[{header:\"Cookie\",operation:\"set\",value:e}]",
      "anchor_byte_zero_based": 563455,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 563455,
      "excerpt_end_byte_exclusive": 563638,
      "note": "Dynamic rule code is in the downloadable package and is inspectable; empty rules.json does not make these paths invisible to review.",
      "reading": "The extension constructs dynamic request-header rules supporting its authenticated requests."
    },
    {
      "id": "SC15",
      "title": "Trade-cookie read and local request counter",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "TRADE_REQUEST_LIMIT_COUNT:0",
      "anchor_byte_zero_based": 566554,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 566554,
      "excerpt_end_byte_exclusive": 567191,
      "note": "",
      "reading": "The client reads the trade cookie and maintains a local request counter."
    },
    {
      "id": "SC16",
      "title": "Price upload has response-driven delay",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "https://items.steaminventoryhelper.com/prices/v2/update",
      "anchor_byte_zero_based": 1965617,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1965617,
      "excerpt_end_byte_exclusive": 1966087,
      "note": "Price collection and WSS task results are separate verified paths. A direct merge of every task result into this database was not established.",
      "reading": "A separate price-observation upload path processes a response-specified delay."
    },
    {
      "id": "SC17",
      "title": "Backup serializes stored maFile records",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "gP(this,\"makeBackUp\"",
      "anchor_byte_zero_based": 1474594,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1474594,
      "excerpt_end_byte_exclusive": 1475734,
      "note": "getAllWithKeys returns stored values. Base64 is not encryption; it can wrap already-encrypted values.",
      "reading": "The backup function serializes stored account records and a manifest before transmitting a Base64-wrapped payload."
    },
    {
      "id": "SC18",
      "title": "Backup base endpoint",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "gP(wP,\"apiUrl\",\"https://core.sih.app/sih/backups\")",
      "anchor_byte_zero_based": 1476301,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1476301,
      "excerpt_end_byte_exclusive": 1476351,
      "note": "",
      "reading": "The backup helper has a server-side destination configured in the bundle."
    },
    {
      "id": "SC19",
      "title": "Raw IndexedDB cursor records",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "sO(this,\"getAllWithKeys\"",
      "anchor_byte_zero_based": 1331750,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1331750,
      "excerpt_end_byte_exclusive": 1332249,
      "note": "",
      "reading": "The IndexedDB helper returns stored values together with their keys, establishing what the backup routine reads."
    },
    {
      "id": "SC20",
      "title": "SDA encryption before storage",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "VP(YP,\"buildEncryptedMaFiles\"",
      "anchor_byte_zero_based": 1524154,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1524154,
      "excerpt_end_byte_exclusive": 1525108,
      "note": "Passkey supplied => encryptData result stored; no passkey => object stored. Unlocking does not itself rewrite stored ciphertext as plaintext.",
      "reading": "When a passkey is supplied, the storage path writes the encryption result. Otherwise, the path can write the object."
    },
    {
      "id": "SC21",
      "title": "Cloud setting defaults false and checks encryption",
      "file": "dist/assets/popup.159a19fc.js",
      "file_sha256": "8eda3d15633c24f1b13de2c185bab91b29242cbc12485dae7378020e006da7fa",
      "anchor": "enabledBackupSDA:!1,enabledSDAShadowMode:!0",
      "anchor_byte_zero_based": 1002487,
      "original_line_one_based": 231,
      "excerpt_start_byte_zero_based": 1002487,
      "excerpt_end_byte_exclusive": 1003140,
      "note": "",
      "reading": "The normal cloud-backup UI starts disabled and checks whether encryption is enabled."
    },
    {
      "id": "SC22",
      "title": "Ordinary import sync checks encrypted manifest and backup switch",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "if(!A.encrypted){t.next=61;break}",
      "anchor_byte_zero_based": 1507557,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1507557,
      "excerpt_end_byte_exclusive": 1507780,
      "note": "",
      "reading": "Ordinary import and synchronization paths check the encrypted manifest and backup preference."
    },
    {
      "id": "SC23",
      "title": "Separate explicit backup message invokes raw backup function",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "makeBackUp:{code:\"BACKGROUND_SDA_MAKE_BACKUP\"",
      "anchor_byte_zero_based": 1822287,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1822287,
      "excerpt_end_byte_exclusive": 1822582,
      "note": "The backup helper itself lacks an encryption assertion. Do not call the entire system proven end-to-end encrypted solely from guarded UI paths.",
      "reading": "A distinct explicit backup message invokes the backup helper; its conditions must be assessed as a separate path."
    },
    {
      "id": "SC24",
      "title": "SDA cipher and KDF",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "crypto.subtle.deriveKey({name:\"PBKDF2\"",
      "anchor_byte_zero_based": 1463199,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1463199,
      "excerpt_end_byte_exclusive": 1463452,
      "note": "",
      "reading": "The authenticator includes a concrete cipher and key-derivation implementation, making its key-handling design inspectable."
    },
    {
      "id": "SC25",
      "title": "SDA constants and auto-confirm defaults",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "YN(zN,\"PBKDF2_ITERATIONS\",5e4)",
      "anchor_byte_zero_based": 1465101,
      "original_line_one_based": 17,
      "excerpt_start_byte_zero_based": 1465101,
      "excerpt_end_byte_exclusive": 1465671,
      "note": "",
      "reading": "Authenticator configuration includes automatic-confirmation settings and their defaults."
    },
    {
      "id": "SC26",
      "title": "Sentry profile extras",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "jf(\"sihAppUserProfile\",Eu.sihAppUserProfile),jf(\"userInfo\",r)",
      "anchor_byte_zero_based": 437403,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 437403,
      "excerpt_end_byte_exclusive": 437464,
      "note": "",
      "reading": "Diagnostics configuration attaches Steam and SIH account context as Sentry extras."
    },
    {
      "id": "SC27",
      "title": "Sentry disables automatic Breadcrumbs integration",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "[\"BrowserApiErrors\",\"TryCatch\",\"Breadcrumbs\",\"GlobalHandlers\"].includes(t.name)",
      "anchor_byte_zero_based": 437765,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 437765,
      "excerpt_end_byte_exclusive": 438069,
      "note": "",
      "reading": "The Sentry setup disables automatic Breadcrumbs, narrowing the activity history collected by that integration."
    },
    {
      "id": "SC28",
      "title": "Russian-language add-funds banner and literal HTTP click URL",
      "file": "js/siteExt/addfunds.bundle.js",
      "file_sha256": "c274980235bfa14acefe1efb546eed6a3b32258ce2cdf5e48acd5cb476d3b863",
      "anchor": "var e,n,t,r=$J(\"html\").attr(\"lang\")",
      "anchor_byte_zero_based": 749,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 749,
      "excerpt_end_byte_exclusive": 1359,
      "note": "This is a language test, not proof of IP geolocation. The HTTP literal is the link destination, not an image-fetch URL.",
      "reading": "The add-funds placement checks Russian page language and links to a literal-IP HTTP destination."
    },
    {
      "id": "SC29",
      "title": "Add-funds banner images come from packaged asset paths",
      "file": "js/siteExt/addfunds.css",
      "file_sha256": "661ddafed2d7dbbdd2b129352d79c021cfccedbe21a44d00d3c80913e593c8c4",
      "anchor": ".sih_lab_banner img.banner1",
      "anchor_byte_zero_based": 285,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 285,
      "excerpt_end_byte_exclusive": 481,
      "note": "",
      "reading": "The advertisement image paths point into packaged assets."
    },
    {
      "id": "SC30",
      "title": "Ad request carries country and language",
      "file": "bundle/js/common.js",
      "file_sha256": "c7f12e778d48dffc105ab3a784b35b4d49967c38d4f1646e405d04126781a976",
      "anchor": "targeting:{f:{country:e.country.toUpperCase(),language:e.lang.toUpperCase()}}",
      "anchor_byte_zero_based": 97063,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 97063,
      "excerpt_end_byte_exclusive": 97140,
      "note": "Shows targeting inputs; does not prove a specific geography-to-creative outcome.",
      "reading": "A general ad-serving request supplies country and language inputs for selection."
    },
    {
      "id": "SC31",
      "title": "Opaque event has inspectable token-return handler",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "Webapi token get: called",
      "anchor_byte_zero_based": 723953,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 723953,
      "excerpt_end_byte_exclusive": 724367,
      "note": "",
      "reading": "An opaque event name maps to a handler that returns a token through the provider’s response path."
    },
    {
      "id": "SC32",
      "title": "Opaque event names map to handlers",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "XA(XA(XA(XA(XA(XA(XA($A,xv,cb)",
      "anchor_byte_zero_based": 1211303,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1211303,
      "excerpt_end_byte_exclusive": 1211463,
      "note": "",
      "reading": "Five opaque event names map to inspectable implementation handlers in this version."
    },
    {
      "id": "SC33",
      "title": "Provider sends heartbeat",
      "file": "bundle/js/background.js",
      "file_sha256": "14bcb727743bd44557466b86eff645074203486f3922223e780bf6d957e741ac",
      "anchor": "pingMessage:JSON.stringify({name:\"ping\"}),pingTime:25e3",
      "anchor_byte_zero_based": 1212997,
      "original_line_one_based": 1,
      "excerpt_start_byte_zero_based": 1212997,
      "excerpt_end_byte_exclusive": 1213052,
      "note": "",
      "reading": "The provider maintains a heartbeat for its connection."
    }
  ],
  "reviewed_files_archive_sha256": "bd01e1f4039eba205772d3690a427d546862616c16e9d9830a3cfd57231de449"
}
