Skip to investigation
PHISHDESTROY / STEAM DOSSIERExtension packages
TECHNICAL APPENDIX / 10 OCTOBER 2026

Steam sessions.
Platform access.

Follow the credential from the user’s browser to the platform’s control layer.

The authenticated Steam session is a renewable source of account access. We inspected the package currently linked by CSGORoll and the official SIH download to identify exactly where a token is read, how it leaves the browser, and what triggers another read.

The author’s audit of this same SIH 2.11.12 specimen — a remotely tasked execution grid over users’ authenticated Steam sessions, with the mass-parsing/Layer-7 abuse-capability question — is retained in full on the case page; this appendix’s code findings are its byte-anchored evidence. The CSGOFast/SIH/Valve case ↗

THE CENTRAL FINDING

A token’s expiry can be temporary. The commercial connection can continue. An available Steam session can supply another credential. The code determines whether collection happens when a popup opens, when a server asks, or when an API request fails.

01 / IDENTIFY THE CODE

The package matters.

Each result is tied to a downloaded version. The acquisition record preserves URLs, timestamps and SHA-256 hashes.

CSGOROLL’S CURRENT LINK

Steam WebAPI
Token Extension 1.2

Offered by Ancient Gaming. The current official redirect ↗ leads here. [A02]

Extension ID
bdgacfnoihldeemdcbggkgmjgdfcliah
Entry point
Popup → index.js → update-token.js
Token path
Steam HTML → popup → clipboard
Integrity
CRX3 proofs verified; ID matches signing key

SHA-256
b3ad7738bd8aa7a7fda1b8db72a51013a002a2bd7a5e85470f3ab1aca038a443

Inspect the extraction path ↓

SIH OFFICIAL DOWNLOAD

Steam Inventory
Helper 2.11.12

The publisher’s website supplies this ZIP and identifies RedBoon Limited. The CSGOFast evidence is examined below. [A07]

Extension ID
cmeakgjggjdlcpncigglobpjbkabhmjl
Entry point
service-worker.js → background bundles
Token path
Steam HTML → handler → SIH WebSocket
Integrity
Official HTTPS ZIP; file hashes recorded

SHA-256
63755fe96c0a55826d45661f8aec56a0b173a833ddf0e64074fd5a798425bd6a

A newer SIH 2.12.1 package was separately acquired from Google’s update service and audited on the case page — three CRX3 signatures verified, extension ID matched. This appendix pins 2.11.12; the 33-finding record for 2.12.1 lives with the case. The CSGOFast/SIH/Valve case ↗

Inspect the server-message path ↓
02 / FOLLOW THE LOGIC

The session is the starting point.

These are reconstructed code paths. They show the downloaded client’s logic, with the conditions needed to reach each step.

TRIGGERUser opens the extension popup.R03 ↗
  1. 01

    Use the existing login

    The extension requests steamcommunity.com/profiles with credentials: 'include'. The browser supplies the eligible Steam session cookies.

  2. 02

    Read Steam’s response

    It extracts the SteamID and data-loyalty_webapi_token from HTML. The value is the live, Steam-issued session credential — account-session material the platform cannot read without the user’s browser.

  3. 03

    Hand the value to the user

    The popup displays the token. A click copies it to the clipboard. Version 1.2 has no registered background worker or automatic platform-upload code.

  4. 04

    Complete the platform handoff

    CSGORoll’s help instructions tell the user to paste the copied token into its inventory page. That website-side submission is the next step, outside this extension’s code. [A06]

CONTROL CONSEQUENCE

The user’s Steam login makes a transferable account credential available for the platform’s verification workflow.

No game-developer account is needed for the extraction path.

This code begins with a user logged into Steam Community. “WebAPI token” names account-session material exposed in that user’s response. It is a different access route from a Steamworks publisher key. The main investigation’s three-column comparison explains those access types.

03 / THE 24-HOUR QUESTION

Validity and collection
have separate triggers.

A token’s exp value describes its validity deadline. A timer, popup action, failed request or server message determines when the client asks for a token again.

What the reviewed evidence establishes
MechanismTriggerObserved evidence
CSGORoll · April 2024 instructionsDaily renewalThe operator instructs users to obtain the token in the same logged-in Steam session and renew it daily. [A04]
CSGORoll · June 2024 announcementAutomatic collection and refreshThe announcement describes background collection and transmission to its servers. The earlier package was not acquired for code inspection. CSGORoll should release the 2024 package that performed the announced automatic collection, together with its collection logs. [A05]
Current linked extension · 1.2Popup opensThe inspected entry point reads the profile token. There is no scheduled 24-hour renewal in this registered path. [R02–R03]
SIH · token-request handlerServer messageThe active handler can extract and return a token on request. The production request cadence is server-side. [S02]
SIH · trade API recoveryHTTP 403 responseReread profile → extract token → update storage → retry. A profile-cache threshold of 60 seconds is separate from token validity. [S04]
SIH · authenticator subsystemExpiry check / explicit refresh callA separate path uses a refresh token and SteamID to request a Steam-issued access token. [S05]
WHAT REPEATS

The client reacquires a credential from Steam. A repeated request may return the same token until Steam rotates it. Continued account access is the condition that makes renewal possible. The audit did not measure a universal 86,400-second lifetime.

04 / BEYOND READING A TOKEN

The active SIH agent
also handles trade commands.

The registered background map contains send, accept, decline and cancel handlers. In the send path, the extension constructs an offer, supplies session material and submits it to Steam. [S06]

SERVER INPUT

Recipient. Items.
Trade message.

The request payload supplies the intended recipient and offer contents.

BROWSER AUTHORITY

Session ID.
Steam cookies.

The client adds session material and sends the request through the authenticated browser context.

SERVER FEEDBACK

Result.
Steam trade ID.

The result is returned to the connected server for its workflow.

The authority here comes from the extension’s browser access and session-backed requests. Steam’s account restrictions and any required mobile confirmation remain part of execution. The audit did not perform a trade.

The session-backed submissions documented here are received by Steam as account-authenticated requests: operator instructions running through user accounts land on Valve’s own endpoints and controls. The CSGOFast/SIH/Valve case ↗

Direct item delivery still sits inside a controlled process.

Credential collection, delivery verification and balance release are distinct steps. The main investigation documents the platform’s settlement rules. The code audit identifies the access mechanisms that can connect a user’s Steam activity to that platform workflow.

05 / CSGOFAST ATTRIBUTION

What is actually
inside the SIH package?

FOUND IN THE DISTRIBUTED FILES

“CSGOFast: Confirm trade”

bundle/js/sihAgent.js contains this notification and a send-trade branch. The current background bundle also contains CSGOFast promotional references. [F01]

CURRENT REGISTRATION

The service worker loads background.js. A package-wide text search found no reference loading sihAgent.js. The active token handler traced here belongs to SIH.

The follow-up now supplies current first-party evidence: CSGOFast’s frontend links the SIH extension and checks its online/permission state. That establishes the present frontend integration. The older bundled CSGOFast branch remains shipped inside the distributed package; CSGOFast’s own frontend establishes the same connection today. Read the current Fast integration findings ↗

06 / REPRODUCIBLE LOCATIONS

Every finding
has a file behind it.

Open a finding for its original file hash, line and byte offset. Optional formatted lines use jsbeautifier 1.15.4; original byte offsets remain the stable reference.

R01The current CSGORoll link identifies a different packageAcquisition record

On 10 October 2026, https://csgoroll.com/extension resolved to Steam WebAPI Token Extension, ID bdgacfnoihldeemdcbggkgmjgdfcliah, offered by Ancient Gaming. The Google update service supplied version 1.2. The June 2024 blog links to the earlier ID cgkgfnlnpcifjnbfdbmcphcgnkeinjpd. The two package identities are recorded separately.

csgoroll-current / manifest.json

Original line 3 · byte 174

Find: "version":"1.2"

SHA-256 ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792

R02The browser session supplies the tokenCode + offline check

Opening the popup loads index.js, which calls getSteamCommunityInfo(). That function requests https://steamcommunity.com/profiles with credentials included, extracts the SteamID and data-loyalty_webapi_token from the returned HTML, and returns both. It reads a Steam-issued value. An offline fixture confirmed that the same response produces the same token.

csgoroll-current / index.html

Original line 51 · byte 1,908

Find: <script src="index.js"

SHA-256 93351ab1c5ac5bcd7b6aae5a7ce6bb7bd7c4f6d0a1e7b8322483c218c2a6bf71

csgoroll-current / index.js

Original line 4 · byte 134 · formatted 5–9

Find: getSteamCommunityInfo().then

SHA-256 b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73

csgoroll-current / update-token.js

Original line 2 · byte 63 · formatted 1–37

Find: getSteamCommunityInfo

SHA-256 a5377f3cc9131c6b9a8d7f3c15268ccc51053bc153310634f3ddda8d059365fc

R03Version 1.2 is a popup-and-clipboard pathRegistered code path

The token is displayed in the popup and copied when the user clicks the copy button. The manifest declares no background worker, no alarms permission and no content scripts. The registered JavaScript contains no daily refresh scheduler or automatic platform upload. CSGORoll’s current help page completes this route with a manual paste into its token field. A separate React template bundle is shipped but is not registered or imported by this entry path.

csgoroll-current / manifest.json

Original line 3 · byte 417

Find: "permissions":[]

SHA-256 ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792

csgoroll-current / index.js

Original line 33 · byte 1,273 · formatted 33–44

Find: navigator.clipboard

SHA-256 b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73

S01SIH runs a privileged background componentManifest + entry point

The official SIH ZIP identifies version 2.11.12. Its service worker imports common.js, background.js and backgroundAngular.js. Its declared capabilities include cookies, storage, webRequest and declarativeNetRequest, with host access to all URLs. The manifest’s complete permission list is notifications, alarms, storage, unlimitedStorage, background, webRequest, declarativeNetRequest, declarativeNetRequestFeedback, cookies, activeTab and management, beside host access to <all_urls>. Those permissions describe available capabilities; the following findings trace specific uses.

sih / manifest.json

Original line 7 · byte 164

Find: "version": "2.11.12"

SHA-256 d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379

sih / manifest.json

Original line 446 · byte 14,563

Find: "permissions"

SHA-256 d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379

sih / service-worker.js

Original line 11 · byte 393

Find: importScripts

SHA-256 03bc8f4d0ab34af3d93c0245ebb58a680b06443348473ea36d87cb975a48b64c

S02A server message can request a WebAPI tokenRegistered handler

In the active background bundle, event Av maps to handler Db. Db requests the Steam profile-edit page, extracts its loyalty WebAPI token, and places the value in a webApiToken response field. The handler map is attached to a WebSocket provider at wss://wss-new.steaminventoryhelper.com. This is a code path for returning a credential to the server when extraction succeeds; this review did not capture a live authenticated exchange.

sih / bundle/js/background.js

Original line 1 · byte 532,222 · formatted 22,939–22,954

Find: Av="vYPRqjhY88H91uTxrcm"

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 723,214 · formatted 32,324–32,354

Find: Webapi token get: called

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,210,623 · formatted 56,880–56,880

Find: Av,Db

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,212,415 · formatted 56,933–56,976

Find: wss://wss-new.steaminventoryhelper.com

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

S03The connection has explicit operating conditionsControl flow

The agent runner checks the sih_app_market_toggle setting and stored Steam authorization before connecting. Its controller also considers server configuration, eligible account cohorts and pending orders. The token handler itself contains no additional project-permission check or per-request confirmation. Server-side authorization and which commands are actually sent remain outside the downloaded client package — the command log and authorization configuration are the operator’s records, and SIH should disclose them.

sih / bundle/js/background.js

Original line 1 · byte 513,763 · formatted 22,093–22,115

Find: e[this.settingName]&&r

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,224,236 · formatted 57,525–57,581

Find: h=f.AVAILABLE_CONTROLLER_LAST_NUMBER_IDS,p=l&&l.steamId

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

S04Trade reads can recover by rereading the profileCode path

SIH stores a webApiToken and supplies it as access_token to IEconService/GetTradeOffers. Its HTTP 403 branch obtains the profile again, extracts a token, updates storage and retries. The shared profile helper has a 60-second cache threshold. These are response-driven and cache-driven mechanisms; this path contains no fixed 24-hour token-renewal timer.

sih / bundle/js/background.js

Original line 1 · byte 328,760 · formatted 12,621–12,679

Find: Date.now()-Vc.ts>=6e4

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 665,071 · formatted 29,396–29,459

Find: Not available web api

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/common.js

Original line 1 · byte 204,323

Find: data-loyalty_webapi_token

SHA-256 f1cfa4c20bef835cb0f0e73445077df9ca103f4bd7ed9bd2f8fad602322b0e8c

S05Refresh-token renewal is a separate implementationSeparate credential path

SIH also contains an authenticator/session-management subsystem. It checks an access token’s exp claim and can request another access token from Steam’s GenerateAccessTokenForApp endpoint using a refresh token and SteamID. This subsystem requires its own session material; the profile-page token extraction path does not itself establish possession of a refresh token.

sih / bundle/js/background.js

Original line 17 · byte 1,483,401 · formatted 69,444–69,457

Find: isTokenExpired error:

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 17 · byte 1,483,633 · formatted 69,458–69,523

Find: refresh_token:e,steamid:r

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

S06The active agent includes trade execution pathsRegistered handlers

The same active handler map registers send, accept, decline and cancel operations. The send path constructs an offer from the payload’s recipient and items, adds the local Steam session ID and recipient trade-link token, and POSTs to Steam with credentials included. The server receives the resulting trade ID. Actual execution remains subject to the active session, agent state and Steam’s checks; final mobile confirmation was not tested.

sih / bundle/js/background.js

Original line 1 · byte 531,972 · formatted 22,939–22,947

Find: dv="tradesend"

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,199,292 · formatted 56,297–56,329

Find: https://steamcommunity.com/tradeoffer/new/send

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,201,080 · formatted 56,397–56,408

Find: partner:s.data.recipient.steamId

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,209,217 · formatted 56,806–56,825

Find: Trade send: called

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

F01What the package establishes about CSGOFastAttribution boundary

The SIH package contains a CSGOFast-labelled notification and send-trade implementation in bundle/js/sihAgent.js, plus CSGOFast promotional references in the active background bundle. A package-wide text search found no registration or import reference to sihAgent.js. The active credential path above belongs to SIH. The current CSGOFast frontend supplies the additional connection evidence: a direct SIH installation link and checks for its online and permission state. This establishes the integration at the frontend; what the backend commands do and who controls the operation are records in SIH’s and CSGOFast’s possession, and both operators should publish them. Inspect the new first-party evidence ↗

sih / bundle/js/sihAgent.js

Original line 1 · byte 364,333 · formatted 14,343–14,422

Find: CSGOFast: Confirm trade

SHA-256 3071af198f4b6f88580971b135728a600b06b5d9ae27e44cdc07a0ecf233406c

sih / bundle/js/background.js

Original line 17 · byte 2,273,840

Find: key:"CSGOFAST"

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

07 / REVIEW METHOD

Pinned artifacts.
Bounded conclusions.

Completed

  • Official referral and download provenance recorded.
  • Package versions and original file SHA-256 hashes captured.
  • Current CRX signatures checked, including the extension-ID key match.
  • Registered entry points and selected credential/trade paths traced.
  • Original CSGORoll extractor run offline against synthetic fixtures: five checks passed.

Not measured

  • Steam’s live token lifetime and rotation cadence.
  • Which messages SIH’s production server sent during the 10 October static audit.
  • Actual account permissions, mobile confirmations or settlement outcomes.
  • Runtime behavior of the earlier CSGORoll package and Fast’s authenticated SIH integration.
  • Every SIH feature or every one of its 225 JavaScript files.

This is a targeted code audit, not a certification of either extension. No browser profile, live token or Steam account was used. No extension was installed. The small offline harness intercepts every request and uses invented input.

The separate 11 October runtime capture of SIH 2.11.12 records the live connection, controller settings, uploads, advertising and OpenID flow. The version ledger connects that capture with this static audit and the signed 2.12.1 follow-up.

08 / PRIMARY RECORDS

Sources and downloads.

  1. A01
    CSGORoll’s current extension redirect ↗

    Observed final URL and timestamp are retained in the audit record.

  2. A02
    Steam WebAPI Token Extension — Chrome Web Store ↗

    Version 1.2; Ancient Gaming; listed update 22 February 2025.

  3. A03
    Current CRX from Google’s update service ↗

    Downloaded package, SHA-256 and signature checks pinned in this report.

  4. A04
    CSGORoll — WebAPI P2P Solution ↗

    10 April 2024. Same-session token extraction and daily renewal instruction.

  5. A05
    CSGORoll — WebAPI Trading Extension ↗

    25 June 2024. Automatic collection, refresh and transmission in the announced workflow.

  6. A06
    CSGORoll Help Center — Steam WebAPI Token ↗

    10 November 2025. Extension copy-and-paste instructions and trade-status use.

  7. A07
    SIH official download page ↗

    The page links directly to the audited ZIP and identifies RedBoon Limited.

  8. A08
    SIH official ZIP ↗

    Downloaded version 2.11.12. This is the audit’s SIH code source.

  9. A09
    SIH — Chrome Web Store ↗

    Published identity and version cross-check.

  10. A10
    Chromium — CRX3 format ↗

    Signed archive layout and extension-ID derivation.

  11. A11
    Chrome — cross-origin network requests ↗

    Extension host permissions and cross-origin request behavior. Host-permission paths do not constrain access to just that path.

  12. A12
    Chrome — cookies API ↗

    Cookie access requires the cookies permission and matching host permissions.

  13. A13
    Chrome — alarms API ↗

    A scheduled callback interval is distinct from the expiry encoded in a token.

AUTHOR / INVESTIGATION / EDITORIAL

Agent Cora

Published by PhishDestroy as part of The Steam Dossier.

Find this case in the dossier map →
Agent CoraFOLLOW THE EVIDENCE.
CONTINUE THE INVESTIGATIONIdentity & AML

Paid entry, identity demands, gift codes and control of withdrawals.