Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Catch Cat - Super Game

caeppcjbpjohbcpcpohjicfdcaglgabf
Risk Score
4.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 10,000
Rating 3.9
Last updated 2026-06-14 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer vladhappy2022@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Install-URL hijack redirects users to mymoneyrain.com/games — classic monetization shell pattern.
  • Uninstall-URL hijack signals ad-tech monetization intent beyond stated game purpose.
  • Privacy policy (Google Sites, generic) admits data collection and third-party sharing without scoping to this extension — worst-case policy.
  • Developer is free-webmail (gmail) with no developer name and no business website; identity unverifiable.
  • External JS hosts (addonup.com, cursorcats.com, mymoneyrain.com) indicate affiliate/ad-tech network reach despite minimal declared permissions.

Evidence

  • install_url_hijack crx onInstalled opens https://mymoneyrain.com/games — game-portal/monetization shell pattern (+2.0 Webstore).
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() called with 3rd-party target — numbered monetization signal (+3.0 Webstore).
  • js_external_hosts crx Extension loads JS from addonup.com, cursorcats.com, mymoneyrain.com — 3 ad/affiliate domains.
  • privacy_policy_generic_admits_sharing store Policy on Google Sites: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
  • free_webmail_no_dev_name store vladhappy2022@gmail.com, developer_name empty, no business website — identity unverifiable (+1.5 Reputation).
  • verified_publisher_featured store verified_publisher=true AND is_featured=true provide -3.0/-2.0 Reputation discounts but capped under v3.5 rule 0c.
  • no_csp_mv3 crx csp_present=false; MV3 has strict defaults so no additional Network penalty applied.
  • installs_10k store 10,000 installs → +1.0 Webstore reach signal.

Permissions Breakdown

  • storage low Stores local game state; no cross-origin data risk alone.

Pillar Scores

Permissions0.30
Reputation6.50
Network0.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:25
Listing SHA f338910cca61…
Force block — not fired
Score recovered no
Elapsed