Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Afiliado Dash

dfenkhmeopgbbdeidfenplgimikkgchn
Risk Score
5.57
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Shopping
Installs
Rating
Last updated
Manifest version MV3
CSP present ✅ yes
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies+webRequest on MercadoPago (payment) and WhatsApp: can intercept auth tokens and financial session data
  • Privacy policy is Google's generic account policy — not scoped to this extension at all; data practices undisclosed
  • Brand impersonation: uses WhatsApp brand without confirmed ownership; not verified publisher
  • connect.sessiontransfer.com in JS external hosts raises session-hijacking concern — domain name is alarming
  • install_url_hijack: onInstalled opens 3rd-party URL; no developer name or email disclosed

Evidence

  • cookies+webRequest on payment/auth hosts manifest cookies+webRequest cover auth.mercadopago.com.br and auth.mercadolivre.com.br — session token interception risk.
  • connect.sessiontransfer.com in js_external_hosts crx Domain name strongly implies session transfer/hijack functionality; not declared in host_permissions.
  • Generic Google privacy policy store privacy_policy_url points to myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true.
  • WhatsApp brand impersonation store brand_mention.is_impersonation=true for WhatsApp; confirmed_owner=false, not verified publisher.
  • install_url_hijack=true manifest onInstalled opens a 3rd-party URL; target not disclosed.
  • No developer identity store developer_name and developer_email are both empty; no accountability signals.
  • Privacy policy D-rule trigger store fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • scripting+cookies on web.whatsapp.com manifest Extension can inject scripts and read cookies on WhatsApp Web — access to private messages.

Permissions Breakdown

  • storage low Local state storage; low risk.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • activeTab medium Grants temporary access to active tab on user gesture.
  • sidePanel low Opens side panel UI; low data-access risk.
  • clipboardWrite medium Can write to clipboard; affiliate link injection plausible.
  • cookies high Can read/write cookies on declared host_permissions including Mercado Livre and WhatsApp.
  • webRequest high Can observe all network requests to declared hosts including auth endpoints.
  • scripting medium Can inject scripts into declared host pages.
  • alarms low Background scheduling; low standalone risk.
  • https://app.afiliadodash.com/* medium Developer-controlled domain; expected for dashboard API.
  • https://api.afiliadodash.com/* medium Developer-controlled API endpoint.
  • https://mercadolivre.com.br/* high Access to major e-commerce platform including auth; cookies+webRequest combo is high risk.
  • https://*.mercadolivre.com.br/* high Broad subdomain access including auth.mercadolivre.com.br.
  • https://mercadolivre.com/* high Same as above for .com TLD.
  • https://*.mercadolivre.com/* high Broad subdomain coverage on .com TLD.
  • https://mercadopago.com.br/* high Payment platform access with cookies+webRequest — critical financial data risk.
  • https://*.mercadopago.com.br/* high Broad subdomains of payment platform including auth.
  • https://web.whatsapp.com/* high Access to messaging platform; can read conversations via scripting.

Pillar Scores

Permissions7.50
Reputation7.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:37
Listing SHA db410da2f7b9…
Force block — not fired
Score recovered no
Elapsed