Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Enhancer for Telegram™

dafiggkhlbbhfcpgggcfeeoliillkabn
Risk Score
5.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 50,000
Rating 3.9
Last updated 2025-05-11 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer grephyr.prj@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses Telegram™ trademark, developer is unaffiliated gmail user with no verified identity.
  • Privacy policy points to Google's own policy — not scoped to this extension; data collection and third-party sharing admitted.
  • Install AND uninstall URL hijack flags present; targets not captured but pattern is consistent with traffic monetization.
  • Developer email is gmail with no business domain; free-webmail floor applies, reputation pillar at 7.5.
  • Maintenance: 13 months since last update (6–24mo band) adds moderate staleness risk.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['telegram'], confirmed_owner=false, developer_domain=gmail.com.
  • install_url_hijack crx install_url_hijack=true, install_url_target=null. Pattern consistent with monetization shell even without captured target.
  • uninstall_url_hijack crx uninstall_url_hijack=true, uninstall_url_target=null. Uninstall redirect to 3rd-party is a scored webstore risk (+3.0).
  • generic_privacy_policy store Policy is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → Privacy pillar 10.0.
  • free_webmail_developer store Developer email grephyr.prj@gmail.com; no business website; reputation floor 7.5 applied.
  • no_csp manifest content_security_policy=null; MV3 so no +2.0 network penalty, but dom_sink risk unmitigated.
  • staleness store months_since_update=13, falls in 6–24mo band → Maintenance pillar 6.0.
  • operator_cluster_dev_email_siblings api sibling_count=0 (compound), but dev_email dimension shows 4 sibling extensions under same gmail address.

Permissions Breakdown

  • storage low Stores extension settings locally; no cross-site data risk.
  • content_scripts *://*.web.telegram.org/* medium Injects JS into Telegram Web; scoped to one origin but can read page content.

Pillar Scores

Permissions1.30
Reputation7.50
Network0.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA d8714d008991…
Force block — not fired
Score recovered no
Elapsed 20.8s