Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Black and White Anime Boy Live Wallpaper

bknfipgldmpileaklpccbehjpjgcjdln
Risk Score
5.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 401
Rating
Last updated 2026-05-09 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer tamyssabillys@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijacks both route to gameograf.com affiliate tracker — classic monetization shell.
  • New-tab override with search permission and gameograf.com in js_external_hosts: ad/affiliate traffic injection likely.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Free-webmail developer (tamyssabillys@gmail.com), no verified publisher, no business domain — no accountability.
  • Extension contacts instagram.com, netflix.com, youtube.com, x.com externally — scope wildly exceeds stated wallpaper function.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → gameograf.com with ovkas UTM params; monetization shell fingerprint.
  • install_url_hijack crx onInstalled opens gameograf.com with ovkas UTM params; forced affiliate redirect on install.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; hijacks every new tab for monetization.
  • search_permission manifest search permission declared alongside newtab override; enables search-provider manipulation.
  • js_external_hosts_mismatch crx Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — far beyond wallpaper scope.
  • generic_privacy_policy store Policy URL is Google account-level policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev_no_business store Developer email tamyssabillys@gmail.com; no verified publisher, no business domain, no accountability path.
  • no_csp manifest content_security_policy is null on MV3 extension; no explicit CSP hardening despite external host contacts.

Permissions Breakdown

  • search medium Allows manipulation of search provider; paired with newtab override creates search-hijack surface.
  • chrome_url_overrides.newtab medium Replaces new-tab page; core monetization vector for this extension type.

Pillar Scores

Permissions3.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 09:26
Listing SHA 256273bf23e4…
Force block — not fired
Score recovered no
Elapsed