Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Luffy Pirate King Awakening Live Wallpaper

bjgiiachhcnhldlbpcpblbghcafoakfl
Risk Score
3.94
Risk Level: Low
Recommendation: 🚫 BLOCK
Category NewTab
Installs 17
Rating
Last updated 2026-05-04 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@ovkas.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijack to gameograf.com ad-tech domain with UTM tracking — classic traffic monetization shell.
  • Privacy policy is Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — generic policy admitting data sharing; triggers +10.0.
  • Operator cluster: 3 sibling extensions under same fingerprint across 12 shared install/uninstall URLs — coordinated NewTab network.
  • NewTab override + search permission with no CSP: broad capability for ad/search injection on every new tab opened.
  • No developer name listed; JS contacts gameograf.com, Instagram, Netflix, YouTube, X — multi-origin reach beyond stated wallpaper function.

Evidence

  • install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=ovkas — ad-tech redirect on install.
  • uninstall_url_hijack manifest setUninstallURL points to https://gameograf.com/?utm_source=ovkas — ad-tech redirect on uninstall.
  • operator_cluster store 3 compound siblings; 12 extensions share same install/uninstall URL — coordinated monetization network.
  • privacy_policy_generic api Policy is Google's own privacy page: scope_extension=false, data_collection=true, third_party_sharing=true.
  • newtab_override manifest chrome_url_overrides.newtab replaces every new tab; paired with search permission enables search hijacking.
  • js_external_hosts crx Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — far beyond wallpaper scope.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • csp_absent manifest content_security_policy is null; no script-src restrictions on MV3 extension.

Permissions Breakdown

  • search medium Allows manipulation of the default search provider; paired with NewTab override this enables search hijacking.
  • chrome_url_overrides.newtab medium Replaces every new-tab page; core vector for traffic monetization and ad injection.

Pillar Scores

Permissions3.50
Reputation6.50
Network4.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Operator Siblings (4)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 03:58
Listing SHA 3964cb4f8551…
Force block — not fired
Score recovered no
Elapsed