Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

telegram downloader - Telegram Download Assistant

fpapnfccelgjjlebjpcoleffhmgjendl
Risk Score
5.69
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category MediaDownloader
Installs 7,000
Rating 4.8
Last updated 2026-03-26 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer brunsonthanh@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation of Telegram by gmail.com developer with no verified ownership.
  • Install and uninstall URL hijack flags set; redirects to unknown third-party destinations.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Content scripts injected into kodepay.io (unexplained payment domain) alongside Telegram; unexplained capability.
  • No CSP present + two innerHTML DOM-XSS sinks; elevated XSS risk on Telegram web origin.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands=['telegram'], developer is gmail.com with no confirmed ownership.
  • install_and_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not disclosed.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • unexplained_kodepay_host manifest host_permissions and content_scripts include https://*.kodepay.io/* — payment domain unrelated to Telegram download.
  • no_csp crx content_security_policy=null (MV3 but no explicit CSP); two innerHTML sinks detected in scanned JS.
  • description_permission_mismatch store Extension promises download functionality but lacks 'downloads' permission.
  • free_webmail_developer store Developer email brunsonthanh@gmail.com; no business domain; gmail.com free webmail.
  • featured_by_google store is_featured_by_google=true; provides partial reputation credit despite other risk signals.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • activeTab low Scoped to user-initiated tab interaction; low risk.
  • https://web.telegram.org/* medium Host access to Telegram web; can read messages/media on that origin.
  • https://*.kodepay.io/* high Unknown third-party payment/backend domain; unexplained presence raises supply-chain risk.
  • https://docs.google.com/* medium Host access to Google Docs; can read document content unrelated to stated function.
  • https://tg-video-downloader.net/* medium External downloader backend; data exfil vector, no disclosed relationship.

Pillar Scores

Permissions3.30
Reputation8.50
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA cb66713524ab…
Force block — not fired
Score recovered no
Elapsed 27.6s