Child Luffy in Winter Live Wallpaper
bpicplogeibhabicoedobpchdkngbhjh
Risk Score
5.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override combined with search override — classic monetization shell; installs/uninstalls tracked via UTM hijack URLs.
- Privacy policy hosted on unrelated domain (haberikra.com), admits data collection + 3rd-party sharing, not scoped to this extension.
- Uninstall and install URL hijack to gameograf.com with UTM parameters — explicit user-tracking on lifecycle events.
- Operator cluster: 3 extensions share same dev email; sibling count signals mass-produced wallpaper/newtab factory.
- innerHTML DOM-XSS sink in popup.js with no CSP — content injection risk if API response is attacker-controlled.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces new-tab page.
- uninstall_url_hijack crx setUninstallURL to https://gameograf.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
- privacy_policy_mismatch store Policy at haberikra.com (unrelated domain); scope_extension=false, data_collection=true, third_party_sharing=true.
- operator_cluster api dev_email matches 3 extensions; compound fingerprint sibling_count=1; factory pattern.
- dom_xss_sink crx innerHTML from variable in js/popup.js; no CSP present (MV3 but csp_present=false).
- no_developer_name store developer_name is empty string; reduces accountability.
- months_since_update store 15 months since last update — stale maintenance window for an active newtab extension.
Permissions Breakdown
- search medium Allows modification of search provider; medium risk on its own.
- host_permissions: https://api.gameograf.com/* low Scoped to developer-controlled API domain; limited blast radius.
- chrome_url_overrides.newtab medium NewTab override replaces browser default; primary monetization vector for this category.
Pillar Scores
Permissions4.00
Reputation4.50
Network2.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (13)
Other extensions sharing this developer's compound fingerprint:
- kenndofkbpgkfhaecjmnjmehhhbnioeh
- ieepfmpmjnjidennkopcbamjjdemhjcf
- chjbfnbpbgjnofhahgblpcifjcbkolcp
- jmokcnonladmkkdlgbalffkjiogfcgha
- aaobffjniaghknbgjdkigmcnapghemfa
- cfbobdhebljlbkhdhnikebhhijocphfo
- ckcailiifgopnblmaeaefimdgnaelcph
- dpkgeginpcjfcgnjicpkfkkbnpailidn
- hmagnnippelpfgkmbdnepolcgjlmbohh
- jimikjehahhdekhbmhpbmbponjcimajc
- jofgjibhmlaeofgmidllemkckkpgnpbd
- iimgbphfdpnahafdmikdjnpfnffnbkcl
- gafbkkfalgndkoilabfhmjjjgeihboed
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 12:34
Listing SHA
f6f9ebd86a9a…
Force block
— not fired
Score recovered
no
Elapsed
—