Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhatsApp™ Scraper & Bulk Sender & Auto Join - ExtBoost

gbfehnilmikecbbenafhoceeckfpoojh
Risk Score
5.49
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Other
Installs 280
Rating 5.0
Last updated 2026-09-02
Manifest version MV3
CSP present ❌ no
Developer exportmyinfohq@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Explicit scraper+bulk-sender for WhatsApp with broad <all_urls> host access — high exfil and spam potential.
  • WhatsApp brand impersonation by unverified gmail developer with no developer name disclosed.
  • Privacy policy admits third-party data sharing but lacks retention disclosure; data collection confirmed.
  • 3 innerHTML DOM-XSS sinks with no CSP present amplify code-quality risk on injected content.
  • Small install count (280) with HIGH-tier permissions is tail-attack-surface anomaly.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer is gmail-hosted, not WhatsApp/Meta.
  • broad_host_access manifest host_permissions https://*/* + content_scripts <all_urls>; scraper function maps to every HTTPS site.
  • free_webmail_dev_no_name store developer_email=exportmyinfohq@gmail.com, developer_name empty; no business identity verifiable.
  • small_install_high_perm api install_perm_anomaly.small_install_high_perm=true; 280 installs with HIGH-tier host permissions.
  • privacy_third_party_sharing crx Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • dom_xss_no_csp crx 3 innerHTML sinks across 3 JS files; csp_present=false amplifies XSS risk per FIX B.
  • external_js_host crx js_external_hosts includes api.ext-api.com and web.whatsapp.com; outbound API contact confirmed.
  • tos_violation_scraper store Extension explicitly states WhatsApp scraping + bulk sending — ToS violation of WhatsApp/Meta platform.

Permissions Breakdown

  • storage low Local data persistence only; low standalone risk.
  • identity medium Can access Google account identity tokens; combined with scraper function raises risk.
  • identity.email medium Reads signed-in user email; unnecessary for stated bulk-messaging purpose.
  • https://*/* high Broad host access across all HTTPS sites; enables cross-site data collection.
  • content_scripts: <all_urls> high Content scripts injected on all URLs; combined with scraper function is high exfil surface.

Pillar Scores

Permissions7.50
Reputation7.00
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:13
Listing SHA d5d4e7049f55…
Force block — not fired
Score recovered no
Elapsed