• kautau@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    4 days ago

    Sure, the extension is a zip that can be downloaded, and you’re correct, it’s an injected react app.

    Generally, you can just beautify / format JS in your editor to get a better look

    If that doesn’t work, usually https://lelinhtinh.github.io/de4js/ is helpful

    This is also certainly one of the places where AI has better application than most of how it’s used today

    Most of the actual logic occurs in popup.bundle.js but there’s a number of files

    But skipping through the boilerplate react and webpack stuff you can find the Supabase specific-code

    Without even beautifying one of the smaller files you immediately see

    And then in the popup code you see

    So it’s definitely just showing you affiliate links to fund itself from what it considers “ethical” alternatives. I also saw Posthog in there which they are using for analytics, but it looks like

    It’s configured to not capture each pageview you go to, so it’s not tracking every site you’re on, it looks like only if you’re browsing amazon or ebay based on the background runner code: