Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Black Hole Astronaut Live Wallpaper

eemekabgbdennnopdokklfgndafeegeh
Risk Score
6.03
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 69
Rating
Last updated 2026-06-20 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer travyanci4@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijack both redirect to gameograf.com ad/monetization portal — classic traffic-monetization shell.
  • Privacy policy is Google's generic account policy, not scoped to this extension — admits data collection and 3rd-party sharing.
  • NewTab override + 'search' permission routes every new tab through developer-controlled page with external JS hosts.
  • External JS hosts include instagram.com, netflix.com, youtube.com, x.com — unexplained reach for a wallpaper extension.
  • Free-webmail developer email (gmail), no verified publisher, no business website; developer_name 'dekuy.com' unverifiable.

Evidence

  • install_url_hijack + uninstall_url_hijack manifest Both install and uninstall events redirect to gameograf.com with UTM tracking — textbook monetization shell pattern.
  • chrome_url_overrides.newtab manifest NewTab override to index.html; combined with search permission and external JS hosts reveals monetization intent.
  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • js_external_hosts crx Extension contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — unexplained for a wallpaper extension.
  • free_webmail_developer store Developer email travyanci4@gmail.com; no verified publisher badge; developer_name dekuy.com unverifiable.
  • new_tab_override_with_monetization manifest NewTab + uninstall/install URL hijack to gameograf.com = classic low-effort traffic-monetization cluster.
  • no_csp crx content_security_policy is null (csp_present=false); MV3 default applies but no explicit CSP declared.
  • operator_fingerprint api Operator fingerprint ties travyanci4@gmail.com to gameograf.com install/uninstall targets and broad social-media host list.

Permissions Breakdown

  • search medium Allows reading/overriding search queries; combined with newtab override elevates risk.
  • chrome_url_overrides.newtab high Replaces every new tab; primary monetization vector for wallpaper/shell extensions.

Pillar Scores

Permissions4.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 12:42
Listing SHA 8a0e157406ea…
Force block — not fired
Score recovered no
Elapsed