Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Fuel Wallet

dldjpboieedgcmpkchcjcbijingjcgok
Risk Score
5.12
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 100,000
Rating 3.0
Last updated 2026-02-06 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer contact@fuel.sh
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • scripting + <all_urls> content_scripts: extension injects code into every site, enabling broad page manipulation.
  • clipboardWrite permission is dangerous for a crypto wallet — enables silent clipboard hijacking for address substitution.
  • install_url_hijack flag set; onInstalled may open a third-party URL.
  • Rating is 3.0 (low) with 100K installs; no verified publisher badge and generic unscoped privacy policy.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — triggers +10.0 privacy.
  • host_permissions_all_urls manifest content_scripts_matches=[<all_urls>] with scripting permission; extension runs on every page.
  • install_url_hijack crx install_url_hijack=true; onInstalled likely opens a URL. Target is null (unresolved).
  • dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in main-CjYtXK6q.js; CSP present (MV3) limits but does not eliminate DOM-XSS risk.
  • external_hosts_10 crx 10 distinct external JS hosts including tinyurl.com, socket.io, links.ethers.org — >3 distinct registrable domains.
  • low_rating store Rating 3.0; no verified publisher; not featured; developer email contact@fuel.sh on resolving domain.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; reputation starts at 5.0 with no discounts available.
  • cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.

Permissions Breakdown

  • storage low Standard local data persistence for wallet state.
  • alarms low Background scheduling; low standalone risk.
  • tabs medium Can read tab URLs and titles across all tabs.
  • clipboardWrite medium Can silently write to clipboard — relevant for crypto address poisoning.
  • scripting high Programmatic script injection into pages; combined with <all_urls> is high risk.
  • <all_urls> (host_permissions) high Broad host access — content scripts injected into every site visited.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA e121039a375f…
Force block — not fired
Score recovered no
Elapsed 26.6s