microsoft / MicrosoftEdge-Extensions

This is a community space for Microsoft Edge Add-ons developers, to share resources and information about building, publishing and growing their Microsoft Edge extension.
MIT License
150 stars 128 forks source link

"Roblox Daily Rewards" is a scam #200

Closed TrygveK closed 2 months ago

TrygveK commented 2 months ago

https://microsoftedge.microsoft.com/addons/detail/roblox-daily-rewards/gfojahdoimefaoeehgdjmlkcpmaaoaik I don't know how you guys couldn't tell this was a scam, it is so obvious.

So, let me get to the point this is just a short version, the code of the extension looks ok until you see that it wants to get the description of https://www.roblox.com/games/76905566879869/BloxFinder-API-Updater the description is apis.roblox.com/universal-app-configuration/v1/behaviors/page-heartbeat-v2/content BUT here is the thing if the extension code want to access this via universal id meaning the creator of the code/extension can just change the description to take for example microsoft.com login/password roblox.com login/password basically everything.

They are using a loophole that you guys HAVE VERIFIED it for a weird reason (please check codes from now on better) meaning they don't change the code meaning they don't need to go through the process again, but just changes the Roblox description.

For the last time PLEASE CHECK what THE API WANTS/FETCH

ManikanthMSFT commented 2 months ago

Hi @TrygveK, thank you for bringing this to our notice!

I kindly request you to please file the complaint using the Reporting Infringement form because if it is not submitted officially using the form, our audit team will not be able to take any action and while filling up the form in the Product/Service/App option, ensure you select ‘Microsoft Store on Windows.’

I hope this helps and if you need any more assistance in publishing your extension, please don’t hesitate to reach out to us!