Challenges do NOT require any bruteforcing/directory fuzzing/massive amounts of traffic unless clearly specified in the challenge information below.
This tiny browser extension is the keeper of a well-hidden secret. We would like to access it from our website, but the extension will only give it to mycompany.invalid which we don't own. Can you help us?
Note: The vulnerability is only exploitable in Google Chrome, not in Mozilla Firefox.
To try out the extension, unpack the ZIP file to a directory. Then go to chrome://extensions/, enable Developer mode, click "Load unpacked" and select the directory.