Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kaiju No.8 Mission Recon Live Wallpaper

ffladngmmcjnohcplndpnadlempeieek
Risk Score
6.24
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 127
Rating
Last updated 2026-05-02 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override hijacks every new tab; paired with 'search' permission enables search traffic monetization via gameograf.com.
  • Uninstall and install URL both redirect to gameograf.com with tracking UTM params — confirmed monetization shell pattern.
  • Privacy policy is Google's generic account policy: scope_extension=false, data_collection=true, third_party_sharing=true — worst-case classification.
  • Free-webmail developer (gmail), no developer name, no business website — unverifiable identity with verified_publisher badge.
  • JS external hosts include major platforms (Netflix, Instagram, YouTube, X) with no stated functional need — anomalous reach.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with ovkas UTM params; classic monetization shell.
  • install_url_hijack manifest onInstalled opens gameograf.com with same ovkas UTM params — double URL hijack confirmed.
  • newtab_override manifest chrome_url_overrides.newtab=index.html; every new tab replaced for traffic monetization.
  • privacy_policy_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_devname store Developer email halilseker3455@gmail.com, developer_name empty, no business domain.
  • js_external_hosts_anomalous crx Extension contacts Netflix, Instagram, YouTube, X, Google — broad platform reach beyond wallpaper function.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
  • verified_publisher_free_webmail store verified_publisher=true but developer domain is gmail.com; discount capped per invariant 0c/0e rules.

Permissions Breakdown

  • search medium Allows search provider interaction; paired with newtab override elevates search hijack risk.
  • chrome_url_overrides.newtab high Replaces new-tab page; core mechanism for traffic monetization and search redirect.

Pillar Scores

Permissions4.00
Reputation7.50
Network4.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:56
Listing SHA 7c6b27e28642…
Force block — not fired
Score recovered no
Elapsed