Nayeon Twice K-pop Wallpaper
ejfpcdphgcnpbefcbailejifnmfcpfbd
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to owhit.com — classic traffic-monetization shell pattern.
- Install URL hijack opens owhit.com on install — unsolicited third-party redirect.
- Privacy policy is Google's own policy (myaccount.google.com) — not scoped to this extension at all; admits data collection and 3rd-party sharing.
- NewTab override with free-webmail developer and no verified publisher identity.
- 7 external JS hosts (chatgpt.com, instagram.com, youtube.com, x.com, owhit.com) far exceeds K-pop wallpaper use case.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL → https://owhit.com/uninstall; 3rd-party uninstall redirect, strong monetization shell indicator.
- install_url_hijack manifest onInstalled opens https://owhit.com/nayeon-twice-k-pop-wallpaper; unsolicited 3rd-party page on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab for 98 installs.
- privacy_policy_generic store Policy URL is Google's own privacy policy (456KB), scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email evrenturhane3@gmail.com — free webmail, no verified publisher, no business domain.
- external_hosts_mismatch crx 7 external JS hosts: chatgpt.com, instagram.com, youtube.com, x.com, owhit.com — far beyond wallpaper function.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit restriction on external host connections.
- new_tab_monetization_shape store NewTab + search override + install/uninstall URL hijack + owhit.com = classic traffic-monetization pattern.
Permissions Breakdown
- search medium Allows reading/modifying search queries; medium risk on its own but paired with newtab override elevates concern.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; primary monetization surface for wallpaper shells.
Pillar Scores
Permissions4.00
Reputation7.50
Network4.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 14:05
Listing SHA
58ae73585c52…
Force block
— not fired
Score recovered
no
Elapsed
—