Super Mario Breaking Bad Style Live Wallpaper
cdhfogkbldooloccoceaglibneecpncp
Risk Score
5.59
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack redirects to owhit.com — classic monetization/tracking shell pattern.
- Install URL hijack opens owhit.com on install — ad-tech install funnel.
- NewTab override combined with 'search' permission enables search-provider monetization.
- Privacy policy is Google's generic account policy — not scoped to this extension at all; data collection + 3rd-party sharing admitted.
- Free-webmail developer (gmail), no verified publisher, no business domain; developer identity unverifiable.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://owhit.com/uninstall; classic monetization shell fingerprint.
- install_url_hijack crx onInstalled opens https://owhit.com/super-mario-breaking-bad-style-live-wallpaper; ad-funnel install hook.
- newtab_override manifest chrome_url_overrides.newtab → index.html; replaces every new tab for monetization opportunity.
- generic_privacy_policy store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev store Developer email melikkaksoy01@gmail.com; no verified publisher badge; no business domain.
- js_external_hosts crx Extension references 8 external hosts including chat.openai.com, instagram.com, netflix.com, youtube.com via owhit.com shell.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
- search_permission_newtab_combo manifest 'search' permission + newtab override on a wallpaper extension is a scope mismatch monetization signal.
Permissions Breakdown
- search medium Allows querying/modifying search provider; medium-risk for a wallpaper/NewTab extension.
- chrome_url_overrides.newtab medium Replaces new-tab page; core vector for ad-monetization NewTab shells.
Pillar Scores
Permissions3.50
Reputation7.50
Network2.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 11:48
Listing SHA
64284b4c542b…
Force block
— not fired
Score recovered
no
Elapsed
—