Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WaLeads

fipcjgnajmkjnnofhejohblljnifhldi
Risk Score
4.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 3.0
Last updated 2026-08-24
Manifest version MV3
CSP present ✅ yes
Developer suporte@multiweb.plus
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall AND install URL hijack both flagged — classic monetization/tracking shell behavior.
  • Privacy policy is Google's own policy (scope_extension=false, admits data collection + 3rd-party sharing) — worst-case privacy pillar score.
  • 12 external JS hosts contacted including catalogo.net, contate.ai, socket.io — broad exfiltration surface from WhatsApp session.
  • Content script runs on WhatsApp Web: can silently read messages, contacts, and lead data.
  • 4-country geo-diversity (BR/CA/DE/US) for extension targeting Brazilian WhatsApp CRM users raises supply-chain concern.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hooks present — monetization/tracking shell pattern (+3.0 + +2.0 Webstore).
  • privacy_policy_generic_google store Policy URL is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
  • js_external_hosts_broad crx 12 distinct external hosts including catalogo.net, contate.ai, painel.wapremium.com.br, pay.roote.com.br, socket.io.
  • content_script_whatsapp manifest Runs on https://web.whatsapp.com/* — can access all messages, contacts, and lead data in session.
  • dom_sink_innerhtml_userctrl crx innerHTML DOM-XSS sink in assets/3825.js; CSP present so +0.5 only (no eval compound).
  • geo_diversity_4_countries crx JS hosts span BR, CA, DE, US — 4 countries, not VPN/translation category → +1.5 Network.
  • rating_3_low store Rating is 3.0; rating_count not available so +1.0 reputation penalty not applied (insufficient data).
  • no_verified_publisher_no_featured store Not verified, not featured; developer domain resolves and is not throwaway; email on business domain.

Permissions Breakdown

  • storage low Stores local extension data; low standalone risk.
  • tabs medium Can read tab URLs and titles; moderate privacy surface.
  • content_scripts:https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read messages and contact data.

Pillar Scores

Permissions2.30
Reputation5.50
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:58
Listing SHA c08c2623004b…
Force block — not fired
Score recovered no
Elapsed