Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Martian Aptos & Sui Wallet Extension

efbglgofoippbgcjepnhiblaibcnclgk
Risk Score
4.38
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Security
Installs 200,000
Rating 4.9
Last updated 2025-06-02 (12 months ago)
Manifest version MV3
CSP present ✅ yes
Developer martianwallet@pontem.network
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3; not patched to fixed_in 1.12.1.
  • High CVE-2026-27601 in underscore@1.8.3 compounds CVE exposure; cve_pillar=7.0 triggers block threshold.
  • Privacy policy fetched but scope_extension==false AND data_collection+third_party_sharing==true → v3.5(D) scores +10 (admits data sharing, unscoped).
  • <all_urls> host permission with content scripts on all URLs gives wallet broad page access on every site visited.
  • DOM-XSS sink (innerHTML with user-controlled variable) in blocker.js; CSP present but does not eliminate runtime DOM risk.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Currently bundled version is unpatched.
  • cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
  • privacy_policy_unscoped_admits_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.
  • host_permission_all_urls manifest <all_urls> host permission + content_scripts on http://*/* and https://*/* — injected on every page.
  • dom_xss_sink crx blocker.js: innerHTML assigned from variable 'n'; DOM-XSS sink with CSP present but not eval-blocking.
  • verified_publisher store verified_publisher=true; months_since_update=12 (<18mo), cap not triggered by staleness alone.
  • mixpanel_telemetry crx External hosts include api-js.mixpanel.com, cdn.mxpnl.com, mixpanel.com — telemetry/analytics endpoints.
  • maintenance_6_12mo store months_since_update=12; falls in 6-12mo band → +3.5 maintenance score.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; relevant for wallet dApp detection but elevated.
  • storage low Stores wallet state locally; standard for a crypto wallet extension.
  • notifications low Transaction/status alerts; expected for wallet UX.
  • <all_urls> (host_permission) high Content scripts injected on every page via content_scripts_matches; broad reach for wallet injection.

Pillar Scores

Permissions5.00
Reputation2.50
Network2.50
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 9c67c274f313…
Force block — not fired
Score recovered no
Elapsed 42.6s