Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hytale Adventure Fantasy Portal & Heroes Live Wallpaper

ckodjmibdaghbpjmffnkihfekloabocf
Risk Score
5.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 13
Rating
Last updated 2026-06-30 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer pelins8391@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to owhit.com — classic monetization/tracking shell pattern.
  • Install URL hijack to owhit.com — opens 3rd-party page on install, ad-monetization signal.
  • Privacy policy is Google's own policy (not scoped to this extension) and admits data collection + 3rd-party sharing.
  • Free-webmail dev (pelins8391@gmail.com) with no verified business; newtab override is high-impact capability.
  • NewTab override with owhit.com install/uninstall hooks indicates traffic-monetization shell.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL points to https://owhit.com/uninstall — 3rd-party monetization/tracking domain.
  • install_url_hijack manifest onInstalled opens https://owhit.com/hytale-adventure-fantasy-portal-heroes-live-wallpaper on 3rd-party domain.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; paired with search permission — monetization shell pattern.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev store Developer email pelins8391@gmail.com; no verified business domain; unverified publisher.
  • js_external_hosts crx Extension references owhit.com alongside youtube.com, netflix.com, instagram.com, x.com, chat.openai.com — typical link-farm newtab.
  • very_low_installs store Only 13 installs; combined with HIGH-capability newtab+search override = tail-attack-surface risk.
  • no_csp manifest content_security_policy is null; MV3 provides some default protection but no explicit CSP declared.

Permissions Breakdown

  • search medium Allows overriding search provider; moderate risk for search hijacking.
  • chrome_url_overrides.newtab medium Replaces new tab page — primary mechanism for traffic/ad-monetization shells.

Pillar Scores

Permissions4.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 14:16
Listing SHA 76162e13a539…
Force block — not fired
Score recovered no
Elapsed