Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dragon Ball Cursor - Custom Anime Cursor for Chrome

fghhbjaoopknmbecbghnhnfapabhjhhg
Risk Score
6.08
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 590
Rating
Last updated 2026-04-22 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer mbilalshah0001@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall+install URL hijack to tabplugins.com — classic traffic-monetization shell pattern.
  • scripting + *://*/* grants full page read/write on every site the user visits.
  • Privacy policy is Google's generic account policy — does not cover this extension at all.
  • Free-webmail dev (gmail), no developer name, numbered alias email (mbilalshah0001) — low accountability.
  • DOM-XSS sink (innerHTML) with no CSP; MV3 default CSP helps but inline sink still present.

Evidence

  • uninstall_url_hijack manifest setUninstallURL → https://tabplugins.com/cursors/ (3rd-party traffic grab).
  • install_url_hijack manifest onInstalled opens https://tabplugins.com/dragon-ball-cursor-custom-anime-cursor-for-chrome/.
  • broad_host_plus_scripting manifest host_permissions *://*/* + scripting permission = full DOM control on all sites.
  • privacy_policy_generic store Policy URL is Google account privacy page (fetched, scope_extension=false, data_collection=true, third_party_sharing=true).
  • developer_identity store No developer name; free-webmail numbered alias mbilalshah0001@gmail.com; no business domain.
  • dom_xss_sink crx innerHTML write in main.4964ab1e.js; no CSP declared.
  • small_install_high_perm api 590 installs + HIGH-tier permissions = tail attack surface flag.
  • verified_publisher_with_webmail store Verified publisher badge present but developer email is free Gmail with numbered alias — low trust signal.

Permissions Breakdown

  • storage low Stores cursor preferences locally; low risk.
  • unlimitedStorage low Extends storage quota; no direct exfil risk alone.
  • scripting high Programmatic script injection into all pages via host_permissions *://*/*.
  • *://*/* (host_permissions) high Broad host access — pairs with scripting for full page read/write on every site.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:02
Listing SHA 14b2e5506962…
Force block — not fired
Score recovered no
Elapsed