MalExt Sentry ← Report Library

RedirectorsHub - SelectorsHub Forced-Tab Ad Network

2026-10-05 adware redirect

Extensions list : https://malext.io/?q=ndgimibanhlabgdgjcpbbndiehljcpfh

FieldValue
Extension NameSelectorsHub
Extension IDndgimibanhlabgdgjcpbbndiehljcpfh
Version Analyzed5.8.3 → 5.8.5
Total Affected Users~400,000 users (Featured on the Chrome Web Store)
AssessmentAdware / potentially unwanted behavior

TL;DR

SelectorsHub is a widely used XPath and CSS selector extension for QA and test automation engineers. Version 5.8.5 contains an advertising system that its Chrome Web Store listing does not disclose.

The extension retrieves destination URLs from selectorshub[.]info at runtime and opens them in background tabs. In the side panel and DevTools panel, each URL is preceded by a five-second overlay that presents it as a "community link" and states "100% Safe, No Spam, No Malware". The destinations observed during testing were paid advertisements. On install and update, server-supplied URLs open without any overlay or user action.

The developer controls these destinations entirely from the server. Three different ad rotations were served during testing, and none required an extension update.

Ad-click tracking and the AI selector-fix feature both send requests to a single host, shubads.testcasehub[.]net. At the time of analysis, that host redirected to blomehairdryers[.]com, an Indonesian gambling site. The operator of the redirect has not been identified.

The extension also calls cookies.getAll({}), reading every browser cookie to locate one of its own. The store listing states that no user data is collected or used.

Business impact

Any workstation running the extension will open web content chosen by a third-party server, and the user is told that content is safe. Neither the organization nor the user can review a destination before it loads. Because the destination list sits outside the code reviewed by Google, a change on the server, whether commercial or the result of compromise, reaches every installation at once. The cookie read and the undisclosed data flows also conflict with the published privacy declaration, which matters for organizations that rely on store disclosures in their vendor risk assessments.

Indicators of Compromise / Technical IOCs

TypeValue
Extension IDndgimibanhlabgdgjcpbbndiehljcpfh
Version5.8.5
Ad controlhxxps://selectorshub[.]info/nodeapp/api/link-ads
Ad inventoryhxxps://selectorshub[.]info/nodeapp/api/all-ads
Trackinghxxps://selectorshub[.]info/nodeapp/api/link/track
Schedulerhxxps://selectorshub[.]info/nodeapp/api/update-settings
Daily counterhxxps://shub.selectorshub[.]info/user/counter
Selector-fix endpointhxxps://shubads.testcasehub[.]net/gpt/fixpath
Related domainselectorshub[.]info
Related domainshub.selectorshub[.]info
Related domainshubads.testcasehub[.]net
Redirect target of shubads.testcasehub[.]netblomehairdryers[.]com*
Observed adtestrigor[.]com with utm_medium=ad&eid=LYFcml

\* Observed during live testing of shubads.testcasehub[.]net, including POST /gpt/fixpath. The apex testcasehub[.]net was not checked separately.

1. Server-controlled forced tabs

Confirmed in source code. There are two paths.

The install and update handler in extension/background.js fetches link-ads and opens every returned URL with no prompt:


function openLink(a){browserType.tabs.create({url:a,active:!1})}

That runs for on_install immediately, and for on_update when the license path calls fetchUpdates(). The uninstall URL is also taken from the same response.

The side panel and the DevTools panel load devtools-panel/update.js. On the server-controlled interval (xf days from update-settings; 2 for slug SH at review time), that script shows an overlay and then opens the URL:


chrome.tabs.create({ url: comUrl, active: false });

The overlay calls the destination a "community link" and displays "100% Safe / No Spam / No Malware" during a 5-second countdown. The URL itself is supplied by the server. This markup is in side-panel/side-shub-panel.html and devtools-panel/shub-panel.html. The placeholder href is https://abc.com.

Testing observation

Three different ad rotations were observed during testing from the same link-ads mechanism. One captured response was:


hxxps://testrigor[.]com/blog/revolutionizing-qa-how-to-create-tests-in-seconds-with-testrigors-generative-ai/?utm_source=testingdaily&utm_medium=ad&eid=LYFcml

A later request to the same endpoint returned empty on_install and on_update arrays. The destination is remotely controlled and can change, or disappear, without an extension update.

The same TestRigor URL is also present in the live all-ads footer inventory. A different TestRigor URL, with utm_medium=trselector&eid=LYFcml, is hardcoded in the panel HTML. Only the captured link-ads body supports calling the generative-AI URL a forced-tab destination.

Impact: the mechanism can send users to unwanted, deceptive, phishing, or malicious destinations if the backend or its ad inventory is compromised.

2. Usage and ad tracking

Confirmed in source code. hitCounterApiIfDateChanged() sends a GET to shub.selectorshub.info/user/counter once per calendar day, with a D: shub header. That is a counter ping, not a browsing report. Ad-click events are reported to link/track and shubads.testcasehub.net/analytics/ads/track.

The package also requests the cookies permission and calls:


cookies.getAll({})

to find one extension-related cookie named selectorshub authentication.

Impact: the extension handles browsing-related data beyond its core selector-generation function and should disclose this accurately. The Chrome Web Store listing says the developer will not collect or use user data.

3. Remote response evaluated as code

Confirmed code path; exploitation not established. The selector-fix feature sends the user's selector to shubads.testcasehub[.]net/gpt/fixpath. In the DevTools panel, if the body parses as JSON and includes a fix field, that value is inserted into a string passed to:


browserType.devtools.inspectedWindow.eval("checkInvalidSelector(`"+b.fix+"`)", ...)

In the side panel, the same fix value is sent to the content script as a check-invalid-selector message instead.

The button is parked off-screen in the supplied 5.8.5 package (.hideMatchCountMsg: top/left: -9999px, z-index: -10).

This is a remote-code-integrity risk if the feature is reachable and the endpoint returns an attacker-controlled fix string.

During live testing, POST /gpt/fixpath returned 301 to blomehairdryers[.]com, an Indonesian gambling site. fetch follows that redirect. The body is HTML, response.json() fails, and the catch path runs the local fixer. The gambling page was not passed to eval.


POST hxxps://shubads.testcasehub[.]net/gpt/fixpath   301
GET  hxxps://blomehairdryers[.]com/                  200

Chrome Web Store concerns

The strongest issues for a store report are:

  1. Unexpected functionality: remotely selected URLs are opened in background tabs, with no prompt on the install and update path.
  2. Misleading presentation: on the side panel and DevTools path, paid or promotional destinations are presented as "community links" with a blanket safety claim.
  3. Data disclosure: a daily counter ping and ad tracking occur alongside broad cookie access, while the store listing says data is not collected or used.
  4. Remote code execution risk: in the DevTools panel, a server-returned fix string is passed to inspectedWindow.eval() if the response is JSON.
  5. Affiliate / advertising transparency: observed URLs contain advertising or affiliate-style tracking parameters and should be clearly disclosed if applicable.

These are policy concerns, not a formal Google determination.

Evidence confidence

FindingConfidenceBasis
Background tabs from remote URLs, no prompt on install/updateConfirmedbackground.js
Side-panel and DevTools countdown, then background tabConfirmedupdate.js, side-shub-panel.html, shub-panel.html
Three ad rotations observedObserved during testingCaptured link-ads responses; later requests were empty
"Community link" / safety wordingConfirmedSide panel and DevTools HTML
Daily counter ping + ad-click trackingConfirmedlogin.js, background.js
Cookie enumerationConfirmedcookies.getAll({})
Remote fix string passed to eval() (DevTools panel)Confirmed code pathdevtools-script.js; only if the response is JSON
Gambling redirectObserved during testing301 from shubads.testcasehub.net; response not evaluated

Key source files

Conclusion

SelectorsHub 5.8.5 is not just a selector-generation tool. The package contains a remote-controlled ad and background-tab mechanism that labels paid destinations as safe and can change them without an extension update.

Combined with ad tracking, broad cookie enumeration, and a hidden remote-response evaluation path, this warrants classification as adware / potentially unwanted behavior with a code-integrity risk.