telegram downloader - Telegram Download Assistant
fpapnfccelgjjlebjpcoleffhmgjendl
Risk Score
5.69
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation of Telegram by gmail.com developer with no verified ownership.
- Install and uninstall URL hijack flags set; redirects to unknown third-party destinations.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Content scripts injected into kodepay.io (unexplained payment domain) alongside Telegram; unexplained capability.
- No CSP present + two innerHTML DOM-XSS sinks; elevated XSS risk on Telegram web origin.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['telegram'], developer is gmail.com with no confirmed ownership.
- install_and_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not disclosed.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- unexplained_kodepay_host manifest host_permissions and content_scripts include https://*.kodepay.io/* — payment domain unrelated to Telegram download.
- no_csp crx content_security_policy=null (MV3 but no explicit CSP); two innerHTML sinks detected in scanned JS.
- description_permission_mismatch store Extension promises download functionality but lacks 'downloads' permission.
- free_webmail_developer store Developer email brunsonthanh@gmail.com; no business domain; gmail.com free webmail.
- featured_by_google store is_featured_by_google=true; provides partial reputation credit despite other risk signals.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- activeTab low Scoped to user-initiated tab interaction; low risk.
- https://web.telegram.org/* medium Host access to Telegram web; can read messages/media on that origin.
- https://*.kodepay.io/* high Unknown third-party payment/backend domain; unexplained presence raises supply-chain risk.
- https://docs.google.com/* medium Host access to Google Docs; can read document content unrelated to stated function.
- https://tg-video-downloader.net/* medium External downloader backend; data exfil vector, no disclosed relationship.
Pillar Scores
Permissions3.30
Reputation8.50
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
cb66713524ab…
Force block
— not fired
Score recovered
no
Elapsed
27.6s