Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tomo And Kazuha Playing Together Genshin Impact Live Wallpaper

anmbpphbmnndcoclafpncbenhalmenon
Risk Score
6.01
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 151
Rating 5.0
Last updated 2026-05-11 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer wilsonchristopher5534@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks both redirect to gameograf.com with UTM tracking — textbook monetization shell.
  • New-tab override combined with 'search' permission captures every search session for ad-monetization.
  • Privacy policy is Google's generic account policy — does not scope to this extension (data_collection+third_party_sharing admitted, scope_extension=false) → +10.0 privacy pillar.
  • Free-webmail developer (gmail) with no verified publisher, no business domain, and no privacy policy scoped to extension.
  • JS external hosts include social/streaming platforms (Instagram, Netflix, YouTube, X) beyond stated wallpaper function.

Evidence

  • install_url_hijack crx onInstalled opens gameograf.com with utm_source=ovkas — affiliate/monetization redirect on install.
  • uninstall_url_hijack crx setUninstallURL points to gameograf.com with same UTM params — 3rd-party tracking on uninstall.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab, primary monetization surface.
  • privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email wilsonchristopher5534@gmail.com — free webmail, no verified publisher, no business site.
  • js_external_hosts_mismatch crx Extension contacts Instagram, Netflix, YouTube, X.com — unrelated to a wallpaper/newtab use case.
  • new_tab_monetization_pattern manifest 'search' permission + newtab override + gameograf UTM hijacks = classic ad-monetization shell cluster.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction on external connectivity.

Permissions Breakdown

  • search medium Allows reading search queries; combined with newtab override creates monetization surface.
  • chrome_url_overrides.newtab high Replaces every new tab with extension page; core mechanism for ad-monetization shells.

Pillar Scores

Permissions3.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:30
Listing SHA 894d1c5e00eb…
Force block — not fired
Score recovered no
Elapsed