# Steam sessions. Platform access.

Canonical: https://phishdestroy.io/steam_dossier/extension-audit
Language: en
Author: Agent Cora
Publisher: PhishDestroy
Published: 11 October 2026

FOLLOW-UP / 10 OCTOBER 2026

### Empire’s session access. Fast’s current SIH connection.

The follow-up examines Trade Token Sync 1.2.4, the background Steam renewal mechanism, old and current Roll availability, and new first-party Fast frontend evidence linking SIH.

[Read the new findings ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html)

TECHNICAL APPENDIX / 10 OCTOBER 2026

Follow the credential from the user’s browser to the platform’s control layer.

The authenticated Steam session is a renewable source of account access. We inspected the package currently linked by CSGORoll and the official SIH download to identify exactly where a token is read, how it leaves the browser, and what triggers another read.

The author’s audit of this same SIH 2.11.12 specimen — a remotely tasked execution grid over users’ authenticated Steam sessions, with the mass-parsing/Layer-7 abuse-capability question — is retained in full on the case page; this appendix’s code findings are its byte-anchored evidence.  [The CSGOFast/SIH/Valve case ↗](https://phishdestroy.io/steam_dossier/csgofast-sih.html)

[Follow the code ↓](https://phishdestroy.io/steam_dossier/extension-audit#traces)  [What does “24 hours” mean?](https://phishdestroy.io/steam_dossier/extension-audit#timing)

REVIEW RECORD **2 packages. Exact versions.**

CSGORoll-linked

1.2 · Google CRX

SIH

2.11.12 · Official ZIP

Method

Static tracing + offline fixtures

Live accounts used

0

[Download evidence record ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/audit-record.json)

THE CENTRAL FINDING

**A token’s expiry can be temporary. The commercial connection can continue.**  An available Steam session can supply another credential. The code determines whether collection happens when a popup opens, when a server asks, or when an API request fails.

01 / IDENTIFY THE CODE

## The package matters.

Each result is tied to a downloaded version. The acquisition record preserves URLs, timestamps and SHA-256 hashes.

CSGOROLL’S CURRENT LINK

### Steam WebAPI Token Extension *1.2*

Offered by Ancient Gaming. The current  [official redirect ↗](https://csgoroll.com/extension)  leads here.  [A02](https://phishdestroy.io/steam_dossier/extension-audit#A02)

Extension ID

bdgacfnoihldeemdcbggkgmjgdfcliah

Entry point

Popup → index.js → update-token.js

Token path

Steam HTML → popup → clipboard

Integrity

CRX3 proofs verified; ID matches signing key

SHA-256 b3ad7738bd8aa7a7fda1b8db72a51013a002a2bd7a5e85470f3ab1aca038a443

[Inspect the extraction path ↓](https://phishdestroy.io/steam_dossier/extension-audit#R02)

SIH OFFICIAL DOWNLOAD

### Steam Inventory Helper *2.11.12*

The publisher’s website supplies this ZIP and identifies RedBoon Limited. The CSGOFast evidence is examined  [below](https://phishdestroy.io/steam_dossier/extension-audit#csgofast) .  [A07](https://phishdestroy.io/steam_dossier/extension-audit#A07)

Extension ID

cmeakgjggjdlcpncigglobpjbkabhmjl

Entry point

service-worker.js → background bundles

Token path

Steam HTML → handler → SIH WebSocket

Integrity

Official HTTPS ZIP; file hashes recorded

SHA-256 63755fe96c0a55826d45661f8aec56a0b173a833ddf0e64074fd5a798425bd6a

A newer SIH 2.12.1 package was separately acquired from Google’s update service and audited on the case page — three CRX3 signatures verified, extension ID matched. This appendix pins 2.11.12; the 33-finding record for 2.12.1 lives with the case.  [The CSGOFast/SIH/Valve case ↗](https://phishdestroy.io/steam_dossier/csgofast-sih.html)

[Inspect the server-message path ↓](https://phishdestroy.io/steam_dossier/extension-audit#S02)

02 / FOLLOW THE LOGIC

## The session is the starting point.

These are reconstructed code paths. They show the downloaded client’s logic, with the conditions needed to reach each step.

CSGORoll-linked · 1.2

SIH · 2.11.12

TRIGGER **User opens the extension popup.**  [R03 ↗](https://phishdestroy.io/steam_dossier/extension-audit#R03)

1. 01

### Use the existing login

The extension requests `steamcommunity.com/profiles` with `credentials: 'include'`. The browser supplies the eligible Steam session cookies.
2. 02

### Read Steam’s response

It extracts the SteamID and `data-loyalty_webapi_token` from HTML. The value is the live, Steam-issued session credential — account-session material the platform cannot read without the user’s browser.
3. 03

### Hand the value to the user

The popup displays the token. A click copies it to the clipboard. Version 1.2 has no registered background worker or automatic platform-upload code.
4. 04

### Complete the platform handoff

CSGORoll’s help instructions tell the user to paste the copied token into its inventory page. That website-side submission is the next step, outside this extension’s code.  [A06](https://phishdestroy.io/steam_dossier/extension-audit#A06)

CONTROL CONSEQUENCE

The user’s Steam login makes a transferable account credential available for the platform’s verification workflow.

TRIGGER **A matching message arrives on the active SIH connection.**  [S02 ↗](https://phishdestroy.io/steam_dossier/extension-audit#S02)

1. 01

### Start the eligible background connection

The runner checks its market setting and stored Steam authorization. Controller state also depends on configuration and orders. The destination is `wss-new.steaminventoryhelper.com`.  [S03](https://phishdestroy.io/steam_dossier/extension-audit#S03)
2. 02

### Dispatch the server message

The active handler map connects the token-request event to `Db`. The handler requests `steamcommunity.com/id/me/edit/info`.
3. 03

### Extract the credential

It matches the loyalty WebAPI token in the response. This handler can proceed only if the request returns the expected authenticated page and token field.
4. 04

### Return it over the same connection

The value enters the response’s `webApiToken` field, alongside the request’s message ID. The send operation uses the SIH WebSocket provider.

CONTROL CONSEQUENCE

The client includes a server-requested credential handoff. The server chooses when to ask; production requests were not captured in the 10 October static audit.

### No game-developer account is needed for the extraction path.

This code begins with a user logged into Steam Community. “WebAPI token” names account-session material exposed in that user’s response. It is a different access route from a Steamworks publisher key. The main investigation’s  [three-column comparison](https://phishdestroy.io/steam_dossier/steam-access.html#credentials)  explains those access types.

03 / THE 24-HOUR QUESTION

## Validity and collection have separate triggers.

A token’s `exp` value describes its validity deadline. A timer, popup action, failed request or server message determines when the client asks for a token again.

What the reviewed evidence establishes

| Mechanism | Trigger | Observed evidence |
| --- | --- | --- |
| CSGORoll · April 2024 instructions | Daily renewal | The operator instructs users to obtain the token in the same logged-in Steam session and renew it daily. [A04](https://phishdestroy.io/steam_dossier/extension-audit#A04) |
| CSGORoll · June 2024 announcement | Automatic collection and refresh | The announcement describes background collection and transmission to its servers. The earlier package was not acquired for code inspection. CSGORoll should release the 2024 package that performed the announced automatic collection, together with its collection logs. [A05](https://phishdestroy.io/steam_dossier/extension-audit#A05) |
| Current linked extension · 1.2 | Popup opens | The inspected entry point reads the profile token. There is no scheduled 24-hour renewal in this registered path. [R02–R03](https://phishdestroy.io/steam_dossier/extension-audit#R02) |
| SIH · token-request handler | Server message | The active handler can extract and return a token on request. The production request cadence is server-side. [S02](https://phishdestroy.io/steam_dossier/extension-audit#S02) |
| SIH · trade API recovery | HTTP 403 response | Reread profile → extract token → update storage → retry. A profile-cache threshold of 60 seconds is separate from token validity. [S04](https://phishdestroy.io/steam_dossier/extension-audit#S04) |
| SIH · authenticator subsystem | Expiry check / explicit refresh call | A separate path uses a refresh token and SteamID to request a Steam-issued access token. [S05](https://phishdestroy.io/steam_dossier/extension-audit#S05) |

WHAT REPEATS

**The client reacquires a credential from Steam.**  A repeated request may return the same token until Steam rotates it. Continued account access is the condition that makes renewal possible. The audit did not measure a universal 86,400-second lifetime.

04 / BEYOND READING A TOKEN

## The active SIH agent also handles trade commands.

The registered background map contains send, accept, decline and cancel handlers. In the send path, the extension constructs an offer, supplies session material and submits it to Steam.  [S06](https://phishdestroy.io/steam_dossier/extension-audit#S06)

SERVER INPUT

### Recipient. Items. Trade message.

The request payload supplies the intended recipient and offer contents.

BROWSER AUTHORITY

### Session ID. Steam cookies.

The client adds session material and sends the request through the authenticated browser context.

SERVER FEEDBACK

### Result. Steam trade ID.

The result is returned to the connected server for its workflow.

The authority here comes from the extension’s browser access and session-backed requests. Steam’s account restrictions and any required mobile confirmation remain part of execution. The audit did not perform a trade.

The session-backed submissions documented here are received by Steam as account-authenticated requests: operator instructions running through user accounts land on Valve’s own endpoints and controls.  [The CSGOFast/SIH/Valve case ↗](https://phishdestroy.io/steam_dossier/csgofast-sih.html)

### Direct item delivery still sits inside a controlled process.

Credential collection, delivery verification and balance release are distinct steps. The main investigation documents  [the platform’s settlement rules](https://phishdestroy.io/steam_dossier/gambling-system.html#settlement-rules) . The code audit identifies the access mechanisms that can connect a user’s Steam activity to that platform workflow.

05 / CSGOFAST ATTRIBUTION

## What is actually inside the SIH package?

FOUND IN THE DISTRIBUTED FILES

### “CSGOFast: Confirm trade”

`bundle/js/sihAgent.js` contains this notification and a send-trade branch. The current background bundle also contains CSGOFast promotional references.  [F01](https://phishdestroy.io/steam_dossier/extension-audit#F01)

CURRENT REGISTRATION

The service worker loads `background.js`. A package-wide text search found no reference loading `sihAgent.js`. The active token handler traced here belongs to SIH.

The follow-up now supplies current first-party evidence: CSGOFast’s frontend links the SIH extension and checks its online/permission state. That establishes the present frontend integration. The older bundled CSGOFast branch remains shipped inside the distributed package; CSGOFast’s own frontend establishes the same connection today.  [Read the current Fast integration findings ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html#fast)

06 / REPRODUCIBLE LOCATIONS

## Every finding has a file behind it.

Open a finding for its original file hash, line and byte offset. Optional formatted lines use jsbeautifier 1.15.4; original byte offsets remain the stable reference.

[Evidence JSON ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/audit-record.json)  [English report ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/audit-report.md)

**R01 The current CSGORoll link identifies a different package Acquisition record**

On 10 October 2026, https://csgoroll.com/extension resolved to Steam WebAPI Token Extension, ID bdgacfnoihldeemdcbggkgmjgdfcliah, offered by Ancient Gaming. The Google update service supplied version 1.2. The June 2024 blog links to the earlier ID cgkgfnlnpcifjnbfdbmcphcgnkeinjpd. The two package identities are recorded separately.

csgoroll-current / manifest.json

Original line 3 · byte 174

Find: `"version":"1.2"`

SHA-256 ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792

**R02 The browser session supplies the token Code + offline check**

Opening the popup loads index.js, which calls getSteamCommunityInfo(). That function requests https://steamcommunity.com/profiles with credentials included, extracts the SteamID and data-loyalty_webapi_token from the returned HTML, and returns both. It reads a Steam-issued value. An offline fixture confirmed that the same response produces the same token.

csgoroll-current / index.html

Original line 51 · byte 1,908

Find: `<script src="index.js"`

SHA-256 93351ab1c5ac5bcd7b6aae5a7ce6bb7bd7c4f6d0a1e7b8322483c218c2a6bf71

csgoroll-current / index.js

Original line 4 · byte 134 · formatted 5–9

Find: `getSteamCommunityInfo().then`

SHA-256 b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73

csgoroll-current / update-token.js

Original line 2 · byte 63 · formatted 1–37

Find: `getSteamCommunityInfo`

SHA-256 a5377f3cc9131c6b9a8d7f3c15268ccc51053bc153310634f3ddda8d059365fc

**R03 Version 1.2 is a popup-and-clipboard path Registered code path**

The token is displayed in the popup and copied when the user clicks the copy button. The manifest declares no background worker, no alarms permission and no content scripts. The registered JavaScript contains no daily refresh scheduler or automatic platform upload. CSGORoll’s current help page completes this route with a manual paste into its token field. A separate React template bundle is shipped but is not registered or imported by this entry path.

csgoroll-current / manifest.json

Original line 3 · byte 417

Find: `"permissions":[]`

SHA-256 ab2ff2f51b5b1ebc862085e992ea380cfb9c42c837fd74c3e9657d9a57eeb792

csgoroll-current / index.js

Original line 33 · byte 1,273 · formatted 33–44

Find: `navigator.clipboard`

SHA-256 b1d899ebd09894ae26d886e67799e724fe4347fc14bc6561074c90531c9d5c73

**S01 SIH runs a privileged background component Manifest + entry point**

The official SIH ZIP identifies version 2.11.12. Its service worker imports common.js, background.js and backgroundAngular.js. Its declared capabilities include cookies, storage, webRequest and declarativeNetRequest, with host access to all URLs. The manifest’s complete permission list is notifications, alarms, storage, unlimitedStorage, background, webRequest, declarativeNetRequest, declarativeNetRequestFeedback, cookies, activeTab and management, beside host access to `<all_urls>`. Those permissions describe available capabilities; the following findings trace specific uses.

sih / manifest.json

Original line 7 · byte 164

Find: `"version": "2.11.12"`

SHA-256 d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379

sih / manifest.json

Original line 446 · byte 14,563

Find: `"permissions"`

SHA-256 d9cd8006b8cfb634943c44c540cf5db9ea425af2a59c8b0def2a8bcdef442379

sih / service-worker.js

Original line 11 · byte 393

Find: `importScripts`

SHA-256 03bc8f4d0ab34af3d93c0245ebb58a680b06443348473ea36d87cb975a48b64c

**S02 A server message can request a WebAPI token Registered handler**

In the active background bundle, event Av maps to handler Db. Db requests the Steam profile-edit page, extracts its loyalty WebAPI token, and places the value in a webApiToken response field. The handler map is attached to a WebSocket provider at wss://wss-new.steaminventoryhelper.com. This is a code path for returning a credential to the server when extraction succeeds; this review did not capture a live authenticated exchange.

sih / bundle/js/background.js

Original line 1 · byte 532,222 · formatted 22,939–22,954

Find: `Av="vYPRqjhY88H91uTxrcm"`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 723,214 · formatted 32,324–32,354

Find: `Webapi token get: called`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,210,623 · formatted 56,880–56,880

Find: `Av,Db`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,212,415 · formatted 56,933–56,976

Find: `wss://wss-new.steaminventoryhelper.com`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

**S03 The connection has explicit operating conditions Control flow**

The agent runner checks the sih_app_market_toggle setting and stored Steam authorization before connecting. Its controller also considers server configuration, eligible account cohorts and pending orders. The token handler itself contains no additional project-permission check or per-request confirmation. Server-side authorization and which commands are actually sent remain outside the downloaded client package — the command log and authorization configuration are the operator’s records, and SIH should disclose them.

sih / bundle/js/background.js

Original line 1 · byte 513,763 · formatted 22,093–22,115

Find: `e[this.settingName]&&r`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,224,236 · formatted 57,525–57,581

Find: `h=f.AVAILABLE_CONTROLLER_LAST_NUMBER_IDS,p=l&&l.steamId`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

**S04 Trade reads can recover by rereading the profile Code path**

SIH stores a webApiToken and supplies it as access_token to IEconService/GetTradeOffers. Its HTTP 403 branch obtains the profile again, extracts a token, updates storage and retries. The shared profile helper has a 60-second cache threshold. These are response-driven and cache-driven mechanisms; this path contains no fixed 24-hour token-renewal timer.

sih / bundle/js/background.js

Original line 1 · byte 328,760 · formatted 12,621–12,679

Find: `Date.now()-Vc.ts>=6e4`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 665,071 · formatted 29,396–29,459

Find: `Not available web api`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/common.js

Original line 1 · byte 204,323

Find: `data-loyalty_webapi_token`

SHA-256 f1cfa4c20bef835cb0f0e73445077df9ca103f4bd7ed9bd2f8fad602322b0e8c

**S05 Refresh-token renewal is a separate implementation Separate credential path**

SIH also contains an authenticator/session-management subsystem. It checks an access token’s exp claim and can request another access token from Steam’s GenerateAccessTokenForApp endpoint using a refresh token and SteamID. This subsystem requires its own session material; the profile-page token extraction path does not itself establish possession of a refresh token.

sih / bundle/js/background.js

Original line 17 · byte 1,483,401 · formatted 69,444–69,457

Find: `isTokenExpired error:`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 17 · byte 1,483,633 · formatted 69,458–69,523

Find: `refresh_token:e,steamid:r`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

**S06 The active agent includes trade execution paths Registered handlers**

The same active handler map registers send, accept, decline and cancel operations. The send path constructs an offer from the payload’s recipient and items, adds the local Steam session ID and recipient trade-link token, and POSTs to Steam with credentials included. The server receives the resulting trade ID. Actual execution remains subject to the active session, agent state and Steam’s checks; final mobile confirmation was not tested.

sih / bundle/js/background.js

Original line 1 · byte 531,972 · formatted 22,939–22,947

Find: `dv="tradesend"`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,199,292 · formatted 56,297–56,329

Find: `https://steamcommunity.com/tradeoffer/new/send`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,201,080 · formatted 56,397–56,408

Find: `partner:s.data.recipient.steamId`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

sih / bundle/js/background.js

Original line 1 · byte 1,209,217 · formatted 56,806–56,825

Find: `Trade send: called`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

**F01 What the package establishes about CSGOFast Attribution boundary**

The SIH package contains a CSGOFast-labelled notification and send-trade implementation in bundle/js/sihAgent.js, plus CSGOFast promotional references in the active background bundle. A package-wide text search found no registration or import reference to sihAgent.js. The active credential path above belongs to SIH. The current CSGOFast frontend supplies the additional connection evidence: a direct SIH installation link and checks for its online and permission state. This establishes the integration at the frontend; what the backend commands do and who controls the operation are records in SIH’s and CSGOFast’s possession, and both operators should publish them.  [Inspect the new first-party evidence ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html#fast)

sih / bundle/js/sihAgent.js

Original line 1 · byte 364,333 · formatted 14,343–14,422

Find: `CSGOFast: Confirm trade`

SHA-256 3071af198f4b6f88580971b135728a600b06b5d9ae27e44cdc07a0ecf233406c

sih / bundle/js/background.js

Original line 17 · byte 2,273,840

Find: `key:"CSGOFAST"`

SHA-256 dffbdddffe00b8d3cbc77fd1963ce25a4513af535e92b951c9df0a5333c69c36

07 / REVIEW METHOD

## Pinned artifacts. Bounded conclusions.

### Completed

- Official referral and download provenance recorded.
- Package versions and original file SHA-256 hashes captured.
- Current CRX signatures checked, including the extension-ID key match.
- Registered entry points and selected credential/trade paths traced.
- Original CSGORoll extractor run offline against synthetic fixtures: five checks passed.

### Not measured

- Steam’s live token lifetime and rotation cadence.
- Which messages SIH’s production server sent during the 10 October static audit.
- Actual account permissions, mobile confirmations or settlement outcomes.
- Runtime behavior of the earlier CSGORoll package and Fast’s authenticated SIH integration.
- Every SIH feature or every one of its 225 JavaScript files.

This is a targeted code audit, not a certification of either extension. No browser profile, live token or Steam account was used. No extension was installed. The small offline harness intercepts every request and uses invented input.

The separate  [11 October runtime capture of SIH 2.11.12](https://phishdestroy.io/steam_dossier/csgofast-sih.html#runtime-capture)  records the live connection, controller settings, uploads, advertising and OpenID flow. The  [version ledger](https://phishdestroy.io/steam_dossier/csgofast-sih.html#evidence-versions)  connects that capture with this static audit and the signed 2.12.1 follow-up.

08 / PRIMARY RECORDS

## Sources and downloads.

1. A01

[CSGORoll’s current extension redirect ↗](https://csgoroll.com/extension)

Observed final URL and timestamp are retained in the audit record.
2. A02

[Steam WebAPI Token Extension — Chrome Web Store ↗](https://chromewebstore.google.com/detail/steam-webapi-token-extens/bdgacfnoihldeemdcbggkgmjgdfcliah)

Version 1.2; Ancient Gaming; listed update 22 February 2025.
3. A03

[Current CRX from Google’s update service ↗](https://clients2.google.com/service/update2/crx?response=redirect&prodversion=140.0.0.0&acceptformat=crx2%2Ccrx3&x=id%3Dbdgacfnoihldeemdcbggkgmjgdfcliah%26uc)

Downloaded package, SHA-256 and signature checks pinned in this report.
4. A04

[CSGORoll — WebAPI P2P Solution ↗](https://www.csgoroll.com/blog/steam-p2p-solution/)

10 April 2024. Same-session token extraction and daily renewal instruction.
5. A05

[CSGORoll — WebAPI Trading Extension ↗](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

25 June 2024. Automatic collection, refresh and transmission in the announced workflow.
6. A06

[CSGORoll Help Center — Steam WebAPI Token ↗](https://intercom.help/csgoroll/en/articles/12033745-steam-webapi-token)

10 November 2025. Extension copy-and-paste instructions and trade-status use.
7. A07

[SIH official download page ↗](https://steaminventoryhelper.com/)

The page links directly to the audited ZIP and identifies RedBoon Limited.
8. A08

[SIH official ZIP ↗](https://download.steaminventoryhelper.com/chrome-extension.zip)

Downloaded version 2.11.12. This is the audit’s SIH code source.
9. A09

[SIH — Chrome Web Store ↗](https://chromewebstore.google.com/detail/steam-inventory-helper/cmeakgjggjdlcpncigglobpjbkabhmjl)

Published identity and version cross-check.
10. A10

[Chromium — CRX3 format ↗](https://raw.githubusercontent.com/chromium/chromium/main/components/crx_file/crx3.proto)

Signed archive layout and extension-ID derivation.
11. A11

[Chrome — cross-origin network requests ↗](https://developer.chrome.com/docs/extensions/develop/concepts/network-requests)

Extension host permissions and cross-origin request behavior. Host-permission paths do not constrain access to just that path.
12. A12

[Chrome — cookies API ↗](https://developer.chrome.com/docs/extensions/reference/api/cookies)

Cookie access requires the cookies permission and matching host permissions.
13. A13

[Chrome — alarms API ↗](https://developer.chrome.com/docs/extensions/reference/api/alarms)

A scheduled callback interval is distinct from the expiry encoded in a token.

[CSGORoll-linked manifest ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/csgoroll-manifest.json)  [SIH manifest ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/sih-manifest.json)  [Signature results ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/crx-verification.json)  [Offline check results ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/extension-audit-2026-10-10/offline-checks.json)
