Minecraft Steve Painting Live Wallpaper
bpkkobhipjhgbhngbennkibepbfhcgjp
Risk Score
6.23
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack to owhit.com — classic monetization shell pattern, scores +3.0 Webstore.
- Install URL hijack to owhit.com — onInstalled opens 3rd-party URL, +2.0 Webstore.
- NewTab override with 8 external JS hosts (Netflix, Instagram, YouTube, OpenAI, X) — ad-aggregator fingerprint.
- Brand impersonation of Minecraft (confirmed_owner==false, gmail dev) — +2.0 Reputation.
- Privacy policy is Google's own policy (generic, scope_extension==false, admits data collection + 3rd-party sharing) — +10.0 Privacy.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://owhit.com/uninstall — 3rd-party hijack, +3.0 Webstore.
- install_url_hijack crx onInstalled opens https://owhit.com/minecraft-steve-painting-live-wallpaper, +2.0 Webstore.
- newtab_override manifest chrome_url_overrides.newtab = index.html; +2.0 Webstore new-tab override with monetization shape.
- brand_impersonation store brand_mention.is_impersonation=true for 'minecraft', confirmed_owner=false, developer is gmail user.
- generic_google_privacy_policy store Policy is myaccount.google.com/privacypolicy — scope_extension=false, admits data collection + 3rd-party sharing.
- js_external_hosts crx 8 external hosts including instagram.com, netflix.com, x.com, chat.openai.com — broad reach for 42-install extension.
- free_webmail_dev store Developer email pelins8391@gmail.com — free webmail, no verified business; reputation floor applies.
- no_csp manifest content_security_policy is null (csp_present=false); MV3 has strict default but no explicit CSP declared.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; paired with NewTab override amplifies monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab with extension-controlled page; primary monetization vector.
Pillar Scores
Permissions4.00
Reputation8.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:19
Listing SHA
a125866f5fbe…
Force block
— not fired
Score recovered
no
Elapsed
—