HashDit
coegijljhiejhdodjbnlglffjomlbgmi
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is a generic freeprivacypolicy.com template admitting data collection and 3rd-party sharing without extension-specific scope — worst-case privacy signal.
- Content script injected on <all_urls> including crypto/banking sites; function_constructor() used in 7 files with no CSP to constrain eval-like patterns.
- Developer domain hashdit.io does not resolve — no verifiable business identity behind a security-critical crypto extension.
- Uninstall URL hijack flag set — extension registers an uninstall URL, opaque destination raises tracking concern.
- react@16.13.1 bundled (below 16.4 threshold check) and no CSP; no CVEs found but DOM-manipulation lib without policy is residual risk.
Evidence
- privacy_policy_generic_admits_collection api freeprivacypolicy.com template: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar per v3.5 rule D.
- developer_domain_not_resolving api hashdit.io resolves=false; cannot verify business identity for security-category extension.
- content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] gives broad page-level JS injection across all sites.
- function_constructor_in_7_files crx new Function() found in background, injected-providers, inject-scripts, message-handler, popup, confirm, highrisk.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() registered; target not captured but pattern flags monetization/tracking risk.
- no_csp_mv3 manifest content_security_policy=null; MV3 default restricts eval but function_constructor findings remain a concern.
- developer_name_internal_group store Developer name 'gextension-push-internal-group' is an internal staging alias, not a public-facing brand.
- js_external_hosts_include_social_cdn crx Contacts api.hashdit.io, dex-bin.bnbstatic.com, github.com, twitter.com — 4 distinct domains, 2 countries.
Permissions Breakdown
- storage low Local state persistence only; no data exfiltration surface on its own.
- content_scripts <all_urls> high Injects JS into every page including banking/crypto sites; high capability reach.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:43
Listing SHA
0281af8cad28…
Force block
— not fired
Score recovered
no
Elapsed
—