Hong Kong Burnout Live Wallpaper
gbeldgdcloiceglhpdnkhbafeoddjehm
Risk Score
4.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override + search permission enables search monetization across 13-sibling operator cluster (50 dev-email siblings).
- Uninstall and install URL hijack to gameograf.com with UTM tracking — confirmed traffic monetization pattern.
- Operator cluster of 13 compound-fingerprint siblings signals mass-produced wallpaper/NewTab shell operation.
- No CSP on MV3 + innerHTML sinks in popup.js and calendar.js expose DOM-XSS surface.
- Developer name absent; verified publisher status limited mitigation given monetization shell pattern.
Evidence
- newtab_override manifest chrome_url_overrides.newtab replaces new-tab page; combined with 'search' permission targets search monetization.
- uninstall_url_hijack crx setUninstallURL → https://gameograf.com/?utm_source=extension&utm_medium=install (3rd-party UTM redirect).
- install_url_hijack crx onInstalled opens https://gameograf.com/?utm_source=extension&utm_medium=install on every install.
- operator_cluster api 13 compound-fingerprint siblings; 50 under same dev email — mass wallpaper/NewTab shell factory.
- dom_xss_sinks crx innerHTML assigned from variable in popup.js and calendar.js; no CSP to mitigate DOM-XSS.
- no_csp manifest content_security_policy is null on MV3; no default-src restriction hardens the XSS sinks.
- verified_publisher_limited store Verified publisher but developer_name empty and monetization shell pattern limits trust discount.
- privacy_policy api Policy fetched; scoped, data_collection+retention+third_party_sharing all true — fully disclosed.
Permissions Breakdown
- search medium Allows reading search queries; combined with NewTab override creates search monetization surface.
- host_permissions: https://api.gameograf.com/* low Scoped to developer's own API domain; limited blast radius.
- chrome_url_overrides.newtab medium Replaces new-tab page; controls user default browsing context and search entry point.
Pillar Scores
Permissions3.50
Reputation3.50
Network2.50
Webstore9.00
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (15)
Other extensions sharing this developer's compound fingerprint:
- fdjpcjggpgdmdikmhoagohakklihimbo
- ammndifopdgpjcpmpbdenfcafipnejlj
- ojhigfemmjpjnmhidflhdlcahgdiiija
- ieocbmlfbinpcffofcjmpbjokkfghodc
- faaegcmakhlmoheamicddkfcmmjoljnd
- amfeinhgbpnnjihjiomibeodnainnjkd
- ceoamfmlgefiljnligpdkdindckojbim
- hlacaekdajdgiiofjplpofbgebgjbnco
- lcoeefcacppckhidgmkdlnbeajkmeick
- kngkldhmcncemclgjgbbogplfeoppkll
- gfcbimjpmoeofbmnjedjfkemdinagkmp
- kmjgnidfglamdnllpoidpfikcodjapih
- heakmhbelclpalglpiceoocofnkcjefb
- epjpkhahnajkdjjfkeadcgfmfjfgdohf
- fjmlhfejlohohljeioedcliggbfkihdf
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 07:28
Listing SHA
e08f3bb090d4…
Force block
— not fired
Score recovered
no
Elapsed
—