RedirectorsHub - SelectorsHub Forced-Tab Ad Network
Extensions list : https://malext.io/?q=ndgimibanhlabgdgjcpbbndiehljcpfh
| Field | Value |
|---|---|
| Extension Name | SelectorsHub |
| Extension ID | ndgimibanhlabgdgjcpbbndiehljcpfh |
| Version Analyzed | 5.8.3 → 5.8.5 |
| Total Affected Users | ~400,000 users (Featured on the Chrome Web Store) |
| Assessment | Adware / potentially unwanted behavior |
TL;DR
SelectorsHub is a widely used XPath and CSS selector extension for QA and test automation engineers. Version 5.8.5 contains an advertising system that its Chrome Web Store listing does not disclose.
The extension retrieves destination URLs from selectorshub[.]info at runtime and opens them in background tabs. In the side panel and DevTools panel, each URL is preceded by a five-second overlay that presents it as a "community link" and states "100% Safe, No Spam, No Malware". The destinations observed during testing were paid advertisements. On install and update, server-supplied URLs open without any overlay or user action.
The developer controls these destinations entirely from the server. Three different ad rotations were served during testing, and none required an extension update.
Ad-click tracking and the AI selector-fix feature both send requests to a single host, shubads.testcasehub[.]net. At the time of analysis, that host redirected to blomehairdryers[.]com, an Indonesian gambling site. The operator of the redirect has not been identified.
The extension also calls cookies.getAll({}), reading every browser cookie to locate one of its own. The store listing states that no user data is collected or used.
Business impact
Any workstation running the extension will open web content chosen by a third-party server, and the user is told that content is safe. Neither the organization nor the user can review a destination before it loads. Because the destination list sits outside the code reviewed by Google, a change on the server, whether commercial or the result of compromise, reaches every installation at once. The cookie read and the undisclosed data flows also conflict with the published privacy declaration, which matters for organizations that rely on store disclosures in their vendor risk assessments.
Indicators of Compromise / Technical IOCs
| Type | Value |
|---|---|
| Extension ID | ndgimibanhlabgdgjcpbbndiehljcpfh |
| Version | 5.8.5 |
| Ad control | hxxps://selectorshub[.]info/nodeapp/api/link-ads |
| Ad inventory | hxxps://selectorshub[.]info/nodeapp/api/all-ads |
| Tracking | hxxps://selectorshub[.]info/nodeapp/api/link/track |
| Scheduler | hxxps://selectorshub[.]info/nodeapp/api/update-settings |
| Daily counter | hxxps://shub.selectorshub[.]info/user/counter |
| Selector-fix endpoint | hxxps://shubads.testcasehub[.]net/gpt/fixpath |
| Related domain | selectorshub[.]info |
| Related domain | shub.selectorshub[.]info |
| Related domain | shubads.testcasehub[.]net |
Redirect target of shubads.testcasehub[.]net | blomehairdryers[.]com* |
| Observed ad | testrigor[.]com with utm_medium=ad&eid=LYFcml |
\* Observed during live testing of shubads.testcasehub[.]net, including POST /gpt/fixpath. The apex testcasehub[.]net was not checked separately.
1. Server-controlled forced tabs
Confirmed in source code. There are two paths.
The install and update handler in extension/background.js fetches link-ads and opens every returned URL with no prompt:
function openLink(a){browserType.tabs.create({url:a,active:!1})}
That runs for on_install immediately, and for on_update when the license path calls fetchUpdates(). The uninstall URL is also taken from the same response.
The side panel and the DevTools panel load devtools-panel/update.js. On the server-controlled interval (xf days from update-settings; 2 for slug SH at review time), that script shows an overlay and then opens the URL:
chrome.tabs.create({ url: comUrl, active: false });
The overlay calls the destination a "community link" and displays "100% Safe / No Spam / No Malware" during a 5-second countdown. The URL itself is supplied by the server. This markup is in side-panel/side-shub-panel.html and devtools-panel/shub-panel.html. The placeholder href is https://abc.com.
Testing observation
Three different ad rotations were observed during testing from the same link-ads mechanism. One captured response was:
hxxps://testrigor[.]com/blog/revolutionizing-qa-how-to-create-tests-in-seconds-with-testrigors-generative-ai/?utm_source=testingdaily&utm_medium=ad&eid=LYFcml
A later request to the same endpoint returned empty on_install and on_update arrays. The destination is remotely controlled and can change, or disappear, without an extension update.
The same TestRigor URL is also present in the live all-ads footer inventory. A different TestRigor URL, with utm_medium=trselector&eid=LYFcml, is hardcoded in the panel HTML. Only the captured link-ads body supports calling the generative-AI URL a forced-tab destination.
Impact: the mechanism can send users to unwanted, deceptive, phishing, or malicious destinations if the backend or its ad inventory is compromised.
2. Usage and ad tracking
Confirmed in source code. hitCounterApiIfDateChanged() sends a GET to shub.selectorshub.info/user/counter once per calendar day, with a D: shub header. That is a counter ping, not a browsing report. Ad-click events are reported to link/track and shubads.testcasehub.net/analytics/ads/track.
The package also requests the cookies permission and calls:
cookies.getAll({})
to find one extension-related cookie named selectorshub authentication.
Impact: the extension handles browsing-related data beyond its core selector-generation function and should disclose this accurately. The Chrome Web Store listing says the developer will not collect or use user data.
3. Remote response evaluated as code
Confirmed code path; exploitation not established. The selector-fix feature sends the user's selector to shubads.testcasehub[.]net/gpt/fixpath. In the DevTools panel, if the body parses as JSON and includes a fix field, that value is inserted into a string passed to:
browserType.devtools.inspectedWindow.eval("checkInvalidSelector(`"+b.fix+"`)", ...)
In the side panel, the same fix value is sent to the content script as a check-invalid-selector message instead.
The button is parked off-screen in the supplied 5.8.5 package (.hideMatchCountMsg: top/left: -9999px, z-index: -10).
This is a remote-code-integrity risk if the feature is reachable and the endpoint returns an attacker-controlled fix string.
During live testing, POST /gpt/fixpath returned 301 to blomehairdryers[.]com, an Indonesian gambling site. fetch follows that redirect. The body is HTML, response.json() fails, and the catch path runs the local fixer. The gambling page was not passed to eval.
POST hxxps://shubads.testcasehub[.]net/gpt/fixpath 301
GET hxxps://blomehairdryers[.]com/ 200
Chrome Web Store concerns
The strongest issues for a store report are:
- Unexpected functionality: remotely selected URLs are opened in background tabs, with no prompt on the install and update path.
- Misleading presentation: on the side panel and DevTools path, paid or promotional destinations are presented as "community links" with a blanket safety claim.
- Data disclosure: a daily counter ping and ad tracking occur alongside broad cookie access, while the store listing says data is not collected or used.
- Remote code execution risk: in the DevTools panel, a server-returned
fixstring is passed toinspectedWindow.eval()if the response is JSON. - Affiliate / advertising transparency: observed URLs contain advertising or affiliate-style tracking parameters and should be clearly disclosed if applicable.
These are policy concerns, not a formal Google determination.
Evidence confidence
| Finding | Confidence | Basis |
|---|---|---|
| Background tabs from remote URLs, no prompt on install/update | Confirmed | background.js |
| Side-panel and DevTools countdown, then background tab | Confirmed | update.js, side-shub-panel.html, shub-panel.html |
| Three ad rotations observed | Observed during testing | Captured link-ads responses; later requests were empty |
| "Community link" / safety wording | Confirmed | Side panel and DevTools HTML |
| Daily counter ping + ad-click tracking | Confirmed | login.js, background.js |
| Cookie enumeration | Confirmed | cookies.getAll({}) |
Remote fix string passed to eval() (DevTools panel) | Confirmed code path | devtools-script.js; only if the response is JSON |
| Gambling redirect | Observed during testing | 301 from shubads.testcasehub.net; response not evaluated |
Key source files
manifest.json: permissions and<all_urls>accessextension/background.js: remote ad retrieval, silent tabs, trackingdevtools-panel/update.js: scheduled countdown and forced-tab flowside-panel/side-shub-panel.html: side-panel "community link" / safety wordingdevtools-panel/shub-panel.html: same overlay in DevToolsdevtools-panel/devtools-script.js: cookie handling, ad logic, selector-fix evaluationdevtools-panel/login.js: daily counter / account flow
Conclusion
SelectorsHub 5.8.5 is not just a selector-generation tool. The package contains a remote-controlled ad and background-tab mechanism that labels paid destinations as safe and can change them without an extension update.
Combined with ad tracking, broad cookie enumeration, and a hidden remote-response evaluation path, this warrants classification as adware / potentially unwanted behavior with a code-integrity risk.