Gmail → Inbox Mirror (multi-account) 항목이 2026-08-15 에 악성 코드 사유로 신고되었습니다.
Admin intervention required immediately. This script is highly malicious spyware disguised as a tool.
> It silently scrapes the user's Gmail Atom feed (`https://mail.google.com/mail/u/${i}/feed/atom`) in the background on every website they visit (`@match *://*/*`).
> It then exfiltrates the user's private email data (Sender, Subject, and Snippet) to an unencrypted, hardcoded 3rd-party IP address (`http://104.251.181.100:59015/api/ingest`) using a hardcoded authentication token (`X-Mirror-Token`).
> It abuses `@grant GM_xmlhttpRequest` and `@connect` to bypass CORS. Please delete this script and permanently ban the author to protect your users.
Gominions (신고된 사용자)의 활동:
이 신고는 관리자에 의해 인정되었지만, 관리자는 사유를 설명 누락, 정보 부족 또는 오해의 소지가 있는 설명(으)로 표시했습니다.
