Hiyuki The First Strike (Wuthering Waves) Live Wallpaper
cbbmincamcgccnmghbohkombblnibkoe
Risk Score
6.40
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall AND install URL hijack both redirect to gameograf.com — confirmed monetization shell pattern.
- NewTab override with search permission: replaces every new tab and can intercept search queries for ad revenue.
- Privacy policy is Google's generic account policy — scope_extension=false, data_collection=true, third_party_sharing=true → worst-case privacy score.
- Developer uses free Gmail account with no business domain; gameograf.com UTM params reveal ad-affiliate tracking.
- Extension contacts google.com, instagram.com, netflix.com, youtube.com, x.com — broad external JS host list typical of monetization shells.
Evidence
- install_url_hijack crx onInstalled opens gameograf.com with UTM ovkas params — confirmed install hijack to ad/monetization domain.
- uninstall_url_hijack crx setUninstallURL points to gameograf.com with UTM ovkas params — confirms monetization shell pattern.
- newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab; core ad-monetization surface.
- privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true — worst case.
- free_webmail_dev store Developer email gizemoge752@gmail.com, no verified publisher, no business domain.
- broad_js_external_hosts crx js_external_hosts includes gameograf.com, instagram.com, netflix.com, youtube.com, x.com — 6 distinct origins.
- search_permission_newtab_combo manifest search permission + newtab override = classic search-monetization fingerprint.
- no_csp crx csp_present=false on MV3 extension; v2 calibration +2.0 Network applied.
Permissions Breakdown
- search medium Enables search provider override/query interception; combined with newtab override = monetization vector.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; core monetization surface for ad/affiliate injection.
Pillar Scores
Permissions4.00
Reputation7.50
Network4.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 08:53
Listing SHA
ba93de77b772…
Force block
— not fired
Score recovered
no
Elapsed
—