Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cyber Guardian

bpgbfkajlonopecnbdldjffkefhkoljb
Risk Score
7.35
Risk Level: High
Recommendation: 🚫 BLOCK
Category Security
Installs 9
Rating
Last updated 2024-10-13 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer cchristinadbluhm@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to cybergrd.com; install-time hijack also set — monetization/tracking shell pattern.
  • webRequest + scripting + <all_urls> with no CSP: full read/inject capability over every site the user visits.
  • Privacy policy URL returns SSL error (unfetchable); effectively no privacy disclosure for a high-capability extension.
  • Free-webmail dev email (gmail), 9 installs, high permissions — strong tail-attack-surface / sleeper signal.
  • JS external hosts include crypto-mining domain (cryptominingfarm.io), ad-tech (adsrv.eacdn.com), and cloaking redirector (bit.ly).

Evidence

  • uninstall_url_hijack + install_url_hijack crx chrome.runtime.setUninstallURL → cybergrd.com/bye/; onInstalled also fires — monetization shell signals.
  • suspicious_js_external_hosts crx Hosts include www.cryptominingfarm.io, wlearnlounge.adsrv.eacdn.com, bgel.moderjat.com, vpn-stream.com.
  • privacy_policy_fetch_error api SSLError on https://cybergrd.com/privacy.html — policy unreachable; scored as no policy (+10.0).
  • free_webmail_dev + small_install_high_perm store cchristinadbluhm@gmail.com; 9 installs; has webRequest+scripting+<all_urls> — tail attack surface.
  • affiliate_hit crx bit.ly in js_external_hosts — generic short-link redirector flagged as affiliate/cloaking.
  • obfuscated_scriptlets crx _0x-style identifiers in two injected scriptlet files across 452 JS files scanned.
  • no_csp manifest content_security_policy is null; MV3 provides some default but no explicit script-src hardening.
  • maintenance_stale store 22 months since last update — falls in 12-24mo band (+6.0).

Permissions Breakdown

  • storage low Standard local data persistence; low standalone risk.
  • unlimitedStorage low Removes storage quota; minor risk unless combined with exfil.
  • webRequest high Can observe all HTTP traffic across all URLs; high surveillance capability.
  • tabs medium Access to tab URLs and metadata; enables browsing history inference.
  • declarativeNetRequest medium Can block/redirect network requests; moderate risk for traffic manipulation.
  • scripting high Programmatic script injection into any page via <all_urls>; very high capability.
  • <all_urls> high Full host access to every site user visits; amplifies all other permissions ×1.2.

Pillar Scores

Permissions8.50
Reputation7.50
Network6.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality3.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:00
Listing SHA dd4e223d7b04…
Force block — not fired
Score recovered no
Elapsed