Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

My Melody Live Wallpaper

dkmkclcinjhocapcmffppjpdcfkcciki
Risk Score
5.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 393
Rating 5.0
Last updated 2025-05-14 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@haberikra.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override with search permission enables full search/ad monetization on every new tab.
  • Uninstall and install URL hijacks redirect to operator marketing site (haberikra.com).
  • Privacy policy is Google's generic policy — does not scope data collection to this extension.
  • No CSP + innerHTML sink (popup.js) creates DOM-XSS exposure.
  • months_since_update=15 with no publisher name increases abandonment/transfer risk.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces every new tab page for all 393 users.
  • uninstall_url_hijack crx setUninstallURL → https://haberikra.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://haberikra.com/?utm_source=install&utm_medium=link&utm_campaign=bg&utm_content=install
  • privacy_policy_generic api Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_csp manifest content_security_policy is null; MV3 default applies but innerHTML sink still exploitable.
  • dom_xss_sink crx js/popup.js: innerHTML assigned from variable with no CSP hardening — DOM-XSS risk.
  • newtab_monetization_shape store search permission + newtab override + install/uninstall hijacks match ad-monetization shell pattern.
  • developer_name_missing store developer_name is empty string; only email (info@haberikra.com) and verified_publisher=true available.

Permissions Breakdown

  • search medium Can override search provider; combined with newtab override enables full search monetization.
  • host_permissions: https://api.gameograf.com/* medium Scoped to single domain but enables data exfil to operator-controlled backend.
  • chrome_url_overrides.newtab medium Replaces every new tab — high REACH, enables ad/search injection on every new tab open.

Pillar Scores

Permissions4.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 16:20
Listing SHA fcaf78c14bc5…
Force block — not fired
Score recovered no
Elapsed