Cute Penguin with Hot Cocoa Live Wallpaper
epjpkhahnajkdjjfkeadcgfmfjfgdohf
Risk Score
5.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Mass newtab-override operator cluster: 14 compound siblings, 50 extensions under same dev email — factory wallpaper shell.
- Privacy policy URL is unreachable (fetch error); effectively no policy — score treated as +10.0.
- Uninstall and install URL hijack both active, redirecting to gameograf.com UTM tracking.
- New-tab override combined with 'search' permission is a classic search-monetization pattern.
- innerHTML DOM-XSS sinks in popup.js and calendar.js with no CSP; injection risk if any input is attacker-controlled.
Evidence
- operator_cluster_siblings api 14 compound siblings, 50 under same dev email — large wallpaper factory cluster (gameograf.com).
- privacy_policy_fetch_failed api Privacy policy URL https://api.gameograf.com/gameograf-privacy-policy.html returned ConnectionError; treated as absent.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install
- newtab_override_plus_search manifest chrome_url_overrides.newtab + 'search' permission; search-monetization shell pattern.
- dom_xss_sinks_no_csp crx innerHTML sinks in popup.js and calendar.js; csp_present==false provides no mitigation.
- verified_publisher store verified_publisher==true but discount capped to -1.0 due to operator cluster monetization shape.
- no_developer_name store developer_name is empty string; reduces accountability signal.
Permissions Breakdown
- search medium Allows reading/modifying search provider; combined with newtab override raises monetization concern.
- chrome_url_overrides.newtab high Replaces every new tab — primary vector for search monetization and traffic hijacking.
- host_permissions: https://api.gameograf.com/* medium Scoped host access to developer API; acceptable but policy URL on same host is unreachable.
Pillar Scores
Permissions4.00
Reputation4.00
Network2.50
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- fdjpcjggpgdmdikmhoagohakklihimbo
- ammndifopdgpjcpmpbdenfcafipnejlj
- ojhigfemmjpjnmhidflhdlcahgdiiija
- ieocbmlfbinpcffofcjmpbjokkfghodc
- faaegcmakhlmoheamicddkfcmmjoljnd
- amfeinhgbpnnjihjiomibeodnainnjkd
- ceoamfmlgefiljnligpdkdindckojbim
- hlacaekdajdgiiofjplpofbgebgjbnco
- lcoeefcacppckhidgmkdlnbeajkmeick
- kngkldhmcncemclgjgbbogplfeoppkll
- gfcbimjpmoeofbmnjedjfkemdinagkmp
- kmjgnidfglamdnllpoidpfikcodjapih
- heakmhbelclpalglpiceoocofnkcjefb
- gbeldgdcloiceglhpdnkhbafeoddjehm
- fjmlhfejlohohljeioedcliggbfkihdf
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 07:33
Listing SHA
40173a5e7fec…
Force block
— not fired
Score recovered
no
Elapsed
—