Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

HashDit

coegijljhiejhdodjbnlglffjomlbgmi
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 795
Rating 5.0
Last updated 2026-04-22 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@hashdit.io
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is a generic freeprivacypolicy.com template admitting data collection and 3rd-party sharing without extension-specific scope — worst-case privacy signal.
  • Content script injected on <all_urls> including crypto/banking sites; function_constructor() used in 7 files with no CSP to constrain eval-like patterns.
  • Developer domain hashdit.io does not resolve — no verifiable business identity behind a security-critical crypto extension.
  • Uninstall URL hijack flag set — extension registers an uninstall URL, opaque destination raises tracking concern.
  • react@16.13.1 bundled (below 16.4 threshold check) and no CSP; no CVEs found but DOM-manipulation lib without policy is residual risk.

Evidence

  • privacy_policy_generic_admits_collection api freeprivacypolicy.com template: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar per v3.5 rule D.
  • developer_domain_not_resolving api hashdit.io resolves=false; cannot verify business identity for security-category extension.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] gives broad page-level JS injection across all sites.
  • function_constructor_in_7_files crx new Function() found in background, injected-providers, inject-scripts, message-handler, popup, confirm, highrisk.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() registered; target not captured but pattern flags monetization/tracking risk.
  • no_csp_mv3 manifest content_security_policy=null; MV3 default restricts eval but function_constructor findings remain a concern.
  • developer_name_internal_group store Developer name 'gextension-push-internal-group' is an internal staging alias, not a public-facing brand.
  • js_external_hosts_include_social_cdn crx Contacts api.hashdit.io, dex-bin.bnbstatic.com, github.com, twitter.com — 4 distinct domains, 2 countries.

Permissions Breakdown

  • storage low Local state persistence only; no data exfiltration surface on its own.
  • content_scripts <all_urls> high Injects JS into every page including banking/crypto sites; high capability reach.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:43
Listing SHA 0281af8cad28…
Force block — not fired
Score recovered no
Elapsed