Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify SHARK - Product scraper & store spy

aingngcmeghkkpbapgdhbidmemoiaahb
Risk Score
4.59
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 3,000
Rating 4.1
Last updated 2024-03-23 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@hypercavs.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension name prominently features 'Shopify' but developer is not Shopify (confirmed_owner=false).
  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — worst-case policy disclosure (+10.0).
  • Extension is 27 months stale (last updated March 2024), placing it in the high-maintenance-risk band.
  • Install URL hijack: onInstalled opens third-party landing page at hypercavs.com (+2.0 webstore).
  • No content_security_policy on MV3 extension that contacts external host and uses scripting permission.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['shopify'], confirmed_owner=false; developer is hypercavs.com.
  • privacy_policy_scope_mismatch api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admitting sharing.
  • install_url_hijack crx install_url_hijack=true; opens https://hypercavs.com/shopify-shark/index.html?chn=chrome-extension on install.
  • stale_extension store months_since_update=27; falls in 24-36mo band (+8.5 maintenance).
  • no_csp manifest content_security_policy=null; MV3 default CSP applies but no explicit policy declared.
  • no_developer_name store developer_name is empty string; raises reputation uncertainty.
  • scripting_permission manifest scripting declared; allows programmatic injection into pages visited by user.
  • cve_findings_empty crx No CVEs detected in bundled JS libraries; cve_findings_raw=[].

Permissions Breakdown

  • activeTab low Grants access only to the current tab when user invokes the extension.
  • identity medium Can access OAuth tokens; risk depends on scopes requested at runtime.
  • storage low Local key-value storage only; no cross-origin exfil by itself.
  • scripting medium Allows programmatic script injection into pages; broad when combined with host perms.
  • https://hypercavs.com/ low Narrow host permission scoped to developer's own domain only.

Pillar Scores

Permissions2.60
Reputation7.00
Network2.00
Webstore6.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA 22abba9a38a5…
Force block — not fired
Score recovered no
Elapsed 22.1s