Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Yashiro Umbrella Toilet Bound Hanako Kun Live Wallpaper

fgpeofejfieffhcpclnkfhghenbpbnka
Risk Score
3.78
Risk Level: Low
Recommendation: 🚫 BLOCK
Category NewTab
Installs 158
Rating
Last updated 2026-06-20 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer halilseker3455@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL both hijacked to gameograf.com ad-monetization site — classic traffic shell pattern.
  • NewTab override + search permission enables full search hijacking/ad injection on every new tab.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection + 3rd-party sharing.
  • Developer uses free Gmail account with no business domain; throwaway-pattern fingerprint.
  • JS contacts gameograf.com plus major social/video platforms (Instagram, Netflix, YouTube, X) — broad external reach from a wallpaper extension.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL → gameograf.com with UTM tracking params; monetization shell indicator.
  • install_url_hijack manifest onInstalled opens gameograf.com with UTM params; traffic-acquisition pattern confirmed.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab replaced by extension page.
  • privacy_policy_generic store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
  • free_webmail_developer store Developer email halilseker3455@gmail.com; no business domain; numbered-alias pattern.
  • js_external_hosts_broad crx JS contacts gameograf.com, instagram.com, netflix.com, youtube.com, x.com — excessive for a wallpaper/NewTab.
  • new_tab_override_with_monetization manifest NewTab + search permission + gameograf.com hijack matches ad-monetization aggregator pattern.
  • csp_absent crx content_security_policy is null (csp_present=false) on MV3; no inline-script protection.

Permissions Breakdown

  • search medium Allows reading/overriding search queries; combined with newtab override enables search hijacking.
  • chrome_url_overrides.newtab high Replaces every new tab with extension page; primary vector for search/ad monetization.

Pillar Scores

Permissions4.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:20
Listing SHA a02b5dbfc30b…
Force block — not fired
Score recovered no
Elapsed