Mycool
banfcjdifkjgmbbbpobnephgghccbkhf
Risk Score
5.90
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search provider hijack: overrides default search to search.mycooltab.com, routing all queries through unknown operator.
- Privacy policy is Google's own policy (not scoped to this extension) and admits data collection and third-party sharing.
- Developer is free-webmail Gmail account with no verifiable business identity or publisher verification.
- Extension is 28 months stale with only 132 installs — zombie search hijacker with no accountability.
- External JS host rx.tycm.homes contacted at runtime; unrecognized domain with no threat intel context.
Evidence
- search_provider_override manifest chrome_settings_overrides sets is_default=true, search_url=search.mycooltab.com — all queries hijacked.
- free_webmail_dev store Developer email fibeyonie@gmail.com; no business website, no verified publisher badge.
- privacy_policy_generic_google api Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated April 2024; 28 months since update with only 132 installs.
- external_js_host crx js_external_hosts includes rx.tycm.homes — unrecognized domain, no bad-host hit but unvetted.
- search_provider_monetization manifest search_url contains src=mycodsv3&type=ds suggesting ad-monetized search intermediary.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
- no_ratings store 0 rating, 132 installs — no community signal to assess legitimacy.
Permissions Breakdown
- chrome_settings_overrides.search_provider (is_default=true) medium Overrides default search engine to search.mycooltab.com; all user searches redirected.
Pillar Scores
Permissions3.00
Reputation8.00
Network0.00
Webstore5.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:37
Listing SHA
32bfd422a100…
Force block
— not fired
Score recovered
no
Elapsed
—