Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

G5 Chat - CRM, automações e ferramentas direto no seu WhatsApp.

afdhcpnimkgccfjcelgkiipidhebddjh
Risk Score
6.34
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 398
Rating 5.0
Last updated 2026-09-04
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Operator cluster of 6 sibling extensions under same dev email — large coordinated attack surface.
  • WhatsApp brand impersonation: confirmed_owner=false, developer is extensao.store not Meta.
  • Privacy policy is Google's own policy — no scope to this extension; data collection & 3rd-party sharing admitted without extension scope.
  • Uninstall URL hijack and install URL hijack detected — classic monetization/tracking shell behavior.
  • new Function() constructor and unguarded innerHTML in content script running inside WhatsApp Web conversations.

Evidence

  • operator_cluster_siblings api 6 sibling extensions share same dev email, install URL, and CSP host-set — coordinated operator cluster.
  • brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer domain extensao.store is not Meta/WhatsApp.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; install_url_hijack also true redirecting to web.whatsapp.com on install.
  • privacy_policy_generic store Policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true — +10.0 privacy.
  • function_constructor crx new Function() in content script running on WhatsApp Web — dynamic code execution risk.
  • dom_sink_innerhtml_no_csp crx innerHTML DOM-XSS sink with csp_present=false — escalated to +2.0 per FIX B.
  • js_external_hosts crx 10 distinct wascript.com.br / watools.com.br endpoints; >3 distinct registrable domains contacted.
  • no_csp_mv3 manifest content_security_policy=null; MV3 so no +2.0 network penalty, but amplifies code findings.

Permissions Breakdown

  • unlimitedStorage low Allows unbounded local storage; low direct harm but can cache sensitive WhatsApp data.
  • storage low Standard key-value storage; low risk on its own.
  • alarms low Scheduled wake-ups; low risk, used for automation timing.
  • tabs medium Can read tab URLs and titles; moderate privacy surface.
  • https://web.whatsapp.com/* medium Host access scoped to WhatsApp Web only; matches stated CRM function but grants full DOM access to all conversations.

Pillar Scores

Permissions2.30
Reputation7.00
Network3.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

sssiednb71b75c7dp727562726963xsx 6.58 High block 2026-09-07
v3.6 6.34 High block 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:23
Listing SHA d712ee559352…
Force block — not fired
Score recovered no
Elapsed