G5 Chat - CRM, automações e ferramentas direto no seu WhatsApp.
afdhcpnimkgccfjcelgkiipidhebddjh
Risk Score
6.34
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 6 sibling extensions under same dev email — large coordinated attack surface.
- WhatsApp brand impersonation: confirmed_owner=false, developer is extensao.store not Meta.
- Privacy policy is Google's own policy — no scope to this extension; data collection & 3rd-party sharing admitted without extension scope.
- Uninstall URL hijack and install URL hijack detected — classic monetization/tracking shell behavior.
- new Function() constructor and unguarded innerHTML in content script running inside WhatsApp Web conversations.
Evidence
- operator_cluster_siblings api 6 sibling extensions share same dev email, install URL, and CSP host-set — coordinated operator cluster.
- brand_impersonation store brand_mention.is_impersonation=true for WhatsApp; developer domain extensao.store is not Meta/WhatsApp.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; install_url_hijack also true redirecting to web.whatsapp.com on install.
- privacy_policy_generic store Policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true — +10.0 privacy.
- function_constructor crx new Function() in content script running on WhatsApp Web — dynamic code execution risk.
- dom_sink_innerhtml_no_csp crx innerHTML DOM-XSS sink with csp_present=false — escalated to +2.0 per FIX B.
- js_external_hosts crx 10 distinct wascript.com.br / watools.com.br endpoints; >3 distinct registrable domains contacted.
- no_csp_mv3 manifest content_security_policy=null; MV3 so no +2.0 network penalty, but amplifies code findings.
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low direct harm but can cache sensitive WhatsApp data.
- storage low Standard key-value storage; low risk on its own.
- alarms low Scheduled wake-ups; low risk, used for automation timing.
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- https://web.whatsapp.com/* medium Host access scoped to WhatsApp Web only; matches stated CRM function but grants full DOM access to all conversations.
Pillar Scores
Permissions2.30
Reputation7.00
Network3.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Scoring History
| sssiednb71b75c7dp727562726963xsx | 6.58 | High | block | 2026-09-07 |
| v3.6 | 6.34 | High | block | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:23
Listing SHA
d712ee559352…
Force block
— not fired
Score recovered
no
Elapsed
—