# Steam sessions. Platform access.

PhishDestroy — targeted extension code audit. Reviewed 10 October 2026.

Credential acquisition, renewal triggers, transmission, registered entry points and related trade-control paths. Not a full security certification of either package.

## Main finding

An authenticated Steam session can supply account credentials repeatedly. A token’s expiry and a client’s collection trigger are separate. The current CSGORoll-linked package reads a Steam response when its popup opens. The inspected SIH background bundle includes a server-requested token-return path and a trade-read retry path after HTTP 403. The audit does not establish a universal 24-hour timer.

## Acquired packages

- **Steam WebAPI Token Extension 1.2** — ID `bdgacfnoihldeemdcbggkgmjgdfcliah`; SHA-256 `b3ad7738bd8aa7a7fda1b8db72a51013a002a2bd7a5e85470f3ab1aca038a443`.
  Official referral: https://csgoroll.com/extension
  Retrieved: 2026-10-10T20:58:38.616218+00:00
  Package: https://clients2.google.com/service/update2/crx?response=redirect&prodversion=140.0.0.0&acceptformat=crx2%2Ccrx3&x=id%3Dbdgacfnoihldeemdcbggkgmjgdfcliah%26uc

- **Steam Inventory Helper 2.11.12** — ID `cmeakgjggjdlcpncigglobpjbkabhmjl`; SHA-256 `63755fe96c0a55826d45661f8aec56a0b173a833ddf0e64074fd5a798425bd6a`.
  Official referral: https://steaminventoryhelper.com/
  Retrieved: 2026-10-10T20:57:26.565433+00:00
  Package: https://download.steaminventoryhelper.com/chrome-extension.zip

## Historical and current timing

| Evidence | Trigger established |
|---|---|
| CSGORoll, 10 April 2024 | Same-session manual extraction; daily renewal instruction. |
| CSGORoll, 25 June 2024 | Announcement of automatic collection, refresh and server transmission; earlier code not acquired. |
| Current CSGORoll-linked 1.2 | Popup opens; extracts existing Steam response token; user copies it. |
| SIH 2.11.12 | Server-requested extraction; HTTP 403 recovery in a trade-read path; separate refresh-token subsystem. |

No game-developer identity is required by the profile-page extraction path. It uses the user’s Steam Community session. These findings concern that credential route, not a Steamworks publisher key.

## R01 — The current CSGORoll link identifies a different package

On 10 October 2026, https://csgoroll.com/extension resolved to Steam WebAPI Token Extension, ID bdgacfnoihldeemdcbggkgmjgdfcliah, offered by Ancient Gaming. The Google update service supplied version 1.2. The June 2024 blog links to the earlier ID cgkgfnlnpcifjnbfdbmcphcgnkeinjpd. The two package identities are recorded separately.

- `csgoroll-current/manifest.json` — original line 3, zero-based byte 174; anchor `"version":"1.2"`.
  SHA-256: `ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792`.

## R02 — The browser session supplies the token

Opening the popup loads index.js, which calls getSteamCommunityInfo(). That function requests https://steamcommunity.com/profiles with credentials included, extracts the SteamID and data-loyalty_webapi_token from the returned HTML, and returns both. It reads a Steam-issued value. An offline fixture confirmed that the same response produces the same token.

- `csgoroll-current/index.html` — original line 51, zero-based byte 1908; anchor `<script src="index.js"`.
  SHA-256: `93351ab1c5ac5bcd7b6aae5a7ce6bb7bd7c4f6d0a1e7b8322483c218c2a6bf71`.
- `csgoroll-current/index.js` — original line 4, zero-based byte 134; anchor `getSteamCommunityInfo().then`.
  SHA-256: `b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73`.
- `csgoroll-current/update-token.js` — original line 2, zero-based byte 63; anchor `getSteamCommunityInfo`.
  SHA-256: `a5377f3cc9131c6b9a8d7f3c15268ccc51053bc153310634f3ddda8d059365fc`.

## R03 — Version 1.2 is a popup-and-clipboard path

The token is displayed in the popup and copied when the user clicks the copy button. The manifest declares no background worker, no alarms permission and no content scripts. The registered JavaScript contains no daily refresh scheduler or automatic platform upload. CSGORoll’s current help page completes this route with a manual paste into its token field. A separate React template bundle is shipped but is not registered or imported by this entry path.

- `csgoroll-current/manifest.json` — original line 3, zero-based byte 417; anchor `"permissions":[]`.
  SHA-256: `ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792`.
- `csgoroll-current/index.js` — original line 33, zero-based byte 1273; anchor `navigator.clipboard`.
  SHA-256: `b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73`.

## S01 — SIH runs a privileged background component

The official SIH ZIP identifies version 2.11.12. Its service worker imports common.js, background.js and backgroundAngular.js. Its declared capabilities include cookies, storage, webRequest and declarativeNetRequest, with host access to all URLs. Those permissions describe available capabilities; the following findings trace specific uses.

- `sih/manifest.json` — original line 7, zero-based byte 164; anchor `"version": "2.11.12"`.
  SHA-256: `d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379`.
- `sih/manifest.json` — original line 446, zero-based byte 14563; anchor `"permissions"`.
  SHA-256: `d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379`.
- `sih/service-worker.js` — original line 11, zero-based byte 393; anchor `importScripts`.
  SHA-256: `03bc8f4d0ab34af3d93c0245ebb58a680b06443348473ea36d87cb975a48b64c`.

## S02 — A server message can request a WebAPI token

In the active background bundle, event Av maps to handler Db. Db requests the Steam profile-edit page, extracts its loyalty WebAPI token, and places the value in a webApiToken response field. The handler map is attached to a WebSocket provider at wss://wss-new.steaminventoryhelper.com. This is a code path for returning a credential to the server when extraction succeeds; this review did not capture a live authenticated exchange.

- `sih/bundle/js/background.js` — original line 1, zero-based byte 532222; anchor `Av="vYPRqjhY88H91uTxrcm"`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 723214; anchor `Webapi token get: called`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 1210623; anchor `Av,Db`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 1212415; anchor `wss://wss-new.steaminventoryhelper.com`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.

## S03 — The connection has explicit operating conditions

The agent runner checks the sih_app_market_toggle setting and stored Steam authorization before connecting. Its controller also considers server configuration, eligible account cohorts and pending orders. The token handler itself contains no additional project-permission check or per-request confirmation. Server-side authorization and which commands are actually sent remain outside the downloaded client package.

- `sih/bundle/js/background.js` — original line 1, zero-based byte 513763; anchor `e[this.settingName]&&r`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 1224236; anchor `h=f.AVAILABLE_CONTROLLER_LAST_NUMBER_IDS,p=l&&l.steamId`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.

## S04 — Trade reads can recover by rereading the profile

SIH stores a webApiToken and supplies it as access_token to IEconService/GetTradeOffers. Its HTTP 403 branch obtains the profile again, extracts a token, updates storage and retries. The shared profile helper has a 60-second cache threshold. These are response-driven and cache-driven mechanisms; this path contains no fixed 24-hour token-renewal timer.

- `sih/bundle/js/background.js` — original line 1, zero-based byte 328760; anchor `Date.now()-Vc.ts>=6e4`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 665071; anchor `Not available web api`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/common.js` — original line 1, zero-based byte 204323; anchor `data-loyalty_webapi_token`.
  SHA-256: `f1cfa4c20bef835cb0f0e73445077df9ca103f4bd7ed9bd2f8fad602322b0e8c`.

## S05 — Refresh-token renewal is a separate implementation

SIH also contains an authenticator/session-management subsystem. It checks an access token’s exp claim and can request another access token from Steam’s GenerateAccessTokenForApp endpoint using a refresh token and SteamID. This subsystem requires its own session material; the profile-page token extraction path does not itself establish possession of a refresh token.

- `sih/bundle/js/background.js` — original line 17, zero-based byte 1483401; anchor `isTokenExpired error:`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 17, zero-based byte 1483633; anchor `refresh_token:e,steamid:r`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.

## S06 — The active agent includes trade execution paths

The same active handler map registers send, accept, decline and cancel operations. The send path constructs an offer from the payload’s recipient and items, adds the local Steam session ID and recipient trade-link token, and POSTs to Steam with credentials included. The server receives the resulting trade ID. Actual execution remains subject to the active session, agent state and Steam’s checks; final mobile confirmation was not tested.

- `sih/bundle/js/background.js` — original line 1, zero-based byte 531972; anchor `dv="tradesend"`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 1199292; anchor `https://steamcommunity.com/tradeoffer/new/send`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 1201080; anchor `partner:s.data.recipient.steamId`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.
- `sih/bundle/js/background.js` — original line 1, zero-based byte 1209217; anchor `Trade send: called`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.

## F01 — What the package establishes about CSGOFast

The SIH package contains a CSGOFast-labelled notification and send-trade implementation in bundle/js/sihAgent.js, plus CSGOFast promotional references in the active background bundle. A package-wide text search found no registration or import reference to sihAgent.js. The active credential path above belongs to SIH; the supplied code does not establish that CSGOFast currently controls that path. A distinct current CSGOFast extension ID or package is still needed to attribute a separate implementation.

- `sih/bundle/js/sihAgent.js` — original line 1, zero-based byte 364333; anchor `CSGOFast: Confirm trade`.
  SHA-256: `3071af198f4b6f88580971b135728a600b06b5d9ae27e44cdc07a0ecf233406c`.
- `sih/bundle/js/background.js` — original line 17, zero-based byte 2273840; anchor `key:"CSGOFAST"`.
  SHA-256: `dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36`.

## Verification and remaining questions

Byte offsets are zero-based in original unmodified files. Line numbers are one-based. Optional formatted lines refer to jsbeautifier 1.15.4 with defaults and are navigational only; hashes refer to original bytes.

Three CRX3 proofs verified; one signing key’s hash matches the current extension ID. Five offline checks passed for the original extraction function. These checks use only invented fixtures, with every fetch intercepted. Cryptographic integrity is not a safety verdict.

- Actual token lifetime and live rotation cadence for a Steam account were not measured.
- The earlier CSGORoll 2024 package was not acquired; its automatic workflow is documented by the operator’s dated publication.
- Current CSGOFast extension identity and attribution of SIH’s active credential handler to CSGOFast are unresolved.
- No live server commands, authenticated Steam requests, trades, account changes or settlement operations were performed.
- The SIH review follows selected credential and trade-control paths, not all 225 JavaScript files or every feature.

## Primary sources

- [A01 — CSGORoll’s current extension redirect](https://csgoroll.com/extension). Observed final URL and timestamp are retained in the audit record.
- [A02 — Steam WebAPI Token Extension — Chrome Web Store](https://chromewebstore.google.com/detail/steam-webapi-token-extens/bdgacfnoihldeemdcbggkgmjgdfcliah). Version 1.2; Ancient Gaming; listed update 22 February 2025.
- [A03 — Current CRX from Google’s update service](https://clients2.google.com/service/update2/crx?response=redirect&prodversion=140.0.0.0&acceptformat=crx2%2Ccrx3&x=id%3Dbdgacfnoihldeemdcbggkgmjgdfcliah%26uc). Downloaded package, SHA-256 and signature checks pinned in this report.
- [A04 — CSGORoll — WebAPI P2P Solution](https://www.csgoroll.com/blog/steam-p2p-solution/). 10 April 2024. Same-session token extraction and daily renewal instruction.
- [A05 — CSGORoll — WebAPI Trading Extension](https://www.csgoroll.com/blog/csgoroll-trading-extension/). 25 June 2024. Automatic collection, refresh and transmission in the announced workflow.
- [A06 — CSGORoll Help Center — Steam WebAPI Token](https://intercom.help/csgoroll/en/articles/12033745-steam-webapi-token). 10 November 2025. Extension copy-and-paste instructions and trade-status use.
- [A07 — SIH official download page](https://steaminventoryhelper.com/). The page links directly to the audited ZIP and identifies RedBoon Limited.
- [A08 — SIH official ZIP](https://download.steaminventoryhelper.com/chrome-extension.zip). Downloaded version 2.11.12. This is the audit’s SIH code source.
- [A09 — SIH — Chrome Web Store](https://chromewebstore.google.com/detail/steam-inventory-helper/cmeakgjggjdlcpncigglobpjbkabhmjl). Published identity and version cross-check.
- [A10 — Chromium — CRX3 format](https://raw.githubusercontent.com/chromium/chromium/main/components/crx_file/crx3.proto). Signed archive layout and extension-ID derivation.
- [A11 — Chrome — cross-origin network requests](https://developer.chrome.com/docs/extensions/develop/concepts/network-requests). Extension host permissions and cross-origin request behavior. Host-permission paths do not constrain access to just that path.
- [A12 — Chrome — cookies API](https://developer.chrome.com/docs/extensions/reference/api/cookies). Cookie access requires the cookies permission and matching host permissions.
- [A13 — Chrome — alarms API](https://developer.chrome.com/docs/extensions/reference/api/alarms). A scheduled callback interval is distinct from the expiry encoded in a token.


## Follow-up: current CSGOFast frontend

The 10 October 2026 follow-up adds first-party Fast code linking the SIH installation ID and checking online/permission state. See [the new findings](../../../trade-tracking.html#fast) and [the new evidence record](../trade-tracking-2026-10-10/audit-record.json). This establishes the frontend integration; it does not establish ownership or the contents of production backend commands. The original package observations above remain dated observations.
