Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Best Blackjack

caiefmpbohoambhdmbgkejacmipnkomb
Risk Score
5.47
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 217
Rating 5.0
Last updated 2026-03-08 (6 months ago)
Manifest version MV3
CSP present ✅ yes
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension (hosted on operator CDN, not dev domain).
  • Uninstall URL hijack flagged AND install URL hijack flagged — classic monetization-shell behavior.
  • Free-webmail developer (gmail), no developer name, no verified business domain.
  • Host permissions span 3 opaque third-party domains (cloudapi.stream ×2, top.rodeo) alongside googleapis.
  • Sandbox CSP allows unsafe-inline + unsafe-eval; manifest name/description are placeholder MSG strings.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hijacks flagged; strong monetization-shell indicator (+3.0+2.0 Webstore).
  • privacy_policy_classification api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (D rule).
  • developer_identity store Free-webmail gmail dev, no developer_name, verified_publisher=true but email is gmail.
  • host_permissions_opaque manifest wheel.cloudapi.stream, mines.cloudapi.stream, top.rodeo are non-Google third-party gambling endpoints.
  • sandbox_csp_unsafe crx Sandbox CSP contains unsafe-inline and unsafe-eval on script-src.
  • manifest_placeholder_strings crx manifest_name and manifest_description are __MSG_name__/__MSG_desc__ — obfuscates true function from store review.
  • js_external_hosts crx 8 external JS hosts including goo.gl shortener and www.harrytheo.com; 3 countries (CA, NL, US).
  • low_install_count store Only 217 installs; tail-attack-surface not flagged by tool but combined with hijacks is suspicious.

Permissions Breakdown

  • identity low OAuth identity; low risk alone, but paired with googleapis host perm enables account data access.
  • https://www.googleapis.com/* medium Broad Google API access; combined with identity permission could read account data.
  • https://wheel.cloudapi.stream/* medium Non-Google third-party host on same CDN serving the privacy policy; unverifiable operator.
  • https://mines.cloudapi.stream/* medium Second cloudapi.stream subdomain; same unverifiable operator cluster.
  • https://top.rodeo/* medium Gambling-adjacent TLD with unknown operator; opaque data destination.

Pillar Scores

Permissions3.00
Reputation7.00
Network2.50
Webstore8.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:59
Listing SHA 985a7a1a45b4…
Force block — not fired
Score recovered no
Elapsed