Kuromi Wallpaper
bjecbajaebnooljcjpnplmjhkogmflfo
Risk Score
5.59
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to owhit.com and install URL hijack — classic NewTab monetization shell pattern.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- New-tab override + search permission with free-webmail dev and no developer name — low accountability.
- JS external hosts include chatgpt.com, instagram.com, netflix.com, youtube.com, x.com — broad reach from a wallpaper extension.
- No developer name supplied; free-webmail (gmail) developer with no business domain identity.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://owhit.com/uninstall — 3rd-party monetization domain.
- install_url_hijack crx onInstalled opens https://owhit.com/kuromi-wallpaper — 3rd-party domain on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new-tab page for all users.
- generic_privacy_policy store Privacy policy is Google's account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- free_webmail_no_dev_name store Developer email nermincandas@gmail.com; developer_name is empty; no business domain.
- broad_js_external_hosts crx JS references chatgpt.com, instagram.com, netflix.com, youtube.com, x.com — excessive for a wallpaper extension.
- search_permission_newtab manifest search permission + newtab override combination is a known NewTab ad-monetization pattern.
- no_csp manifest content_security_policy is null; MV3 provides strict default but no explicit policy declared.
Permissions Breakdown
- search medium Allows overriding search provider; combined with newtab override is a monetization signal.
- chrome_url_overrides.newtab high Replaces new-tab page entirely; primary mechanism for ad-monetization NewTab shells.
Pillar Scores
Permissions5.00
Reputation6.50
Network2.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:19
Listing SHA
c99ae6e9512a…
Force block
— not fired
Score recovered
no
Elapsed
—