Squid Game Netflix 4K Wallpaper
aabgnmkhnpodneeddjlibehbjckckngo
Risk Score
6.94
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Netflix brand impersonation by unverified developer — confirmed is_impersonation flag.
- Uninstall AND install URL hijack both redirect to haberikra.com (monetization/ad-tech domain).
- NewTab override with search override — classic ad-monetization shell pattern.
- Privacy policy is Google's own policy — scope_extension=false, data_collection=true, third_party_sharing=true; scores +10.
- 9 external JS hosts contacted including netflix.com, instagram.com, x.com, youtube.com — far beyond wallpaper function.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'netflix'; developer gameograf.com is not affiliated with Netflix.
- install_uninstall_url_hijack crx Both onInstalled and uninstall URLs redirect to haberikra.com with UTM tracking params.
- newtab_override manifest chrome_url_overrides.newtab=newtab.html replaces every new tab session.
- generic_privacy_policy api Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_external_hosts crx 9 external JS hosts: haberikra.com, netflix.com, instagram.com, youtube.com, x.com, chatgpt.com, etc.
- stale_extension store 16 months since last update; no CVEs but MV3 does not fully mitigate stale+monetization pattern.
- new_tab_monetization_shell manifest Wallpaper theme with newtab+search overrides+hijack URLs is canonical low-effort traffic-monetization pattern.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; only 121 installs, rating unverified.
Permissions Breakdown
- search medium Allows search provider manipulation; paired with NewTab override amplifies search-monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab — primary monetization surface for wallpaper/NewTab shells.
Pillar Scores
Permissions4.00
Reputation7.50
Network3.50
Webstore10.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 09:59
Listing SHA
e59c0478a551…
Force block
— not fired
Score recovered
no
Elapsed
—