Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hello Kitty Live Wallpaper

gnhmgmcijmekpcigeejbneinjikndbpm
Risk Score
6.04
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 575
Rating 5.0
Last updated 2025-05-14 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@haberikra.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override combined with search permission creates monetization/redirect abuse surface.
  • Uninstall and install URL hijacks redirect to haberikra.com with UTM tracking — classic traffic monetization shell.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • No developer name listed; extension title is fan-branded (Hello Kitty) without verified IP ownership.
  • No CSP; innerHTML DOM-XSS sink in popup.js increases XSS risk if any controlled data flows in.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab=newtab.html — extension replaces new-tab page entirely.
  • uninstall_url_hijack crx setUninstallURL → https://haberikra.com/?utm_source=gameograf&utm_medium=link&utm_campaign=bg&utm_content=uninstall
  • install_url_hijack crx onInstalled opens https://haberikra.com/?utm_source=install — 3rd-party URL on install.
  • generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy — not scoped to extension; admits data+3P sharing.
  • no_developer_name store developer_name is empty string; identity unverifiable beyond email domain haberikra.com.
  • fan_content_shell store Title references Hello Kitty (Sanrio IP); no brand ownership confirmed; confirmed is_impersonation=false but unverified.
  • no_csp manifest content_security_policy is null; dom_sink_innerhtml_userctrl found in popup.js with no CSP guard.
  • stale_18mo_verified_publisher_cap api months_since_update=15; verified_publisher=true but discount capped at -1.0 per invariant 0c (>18mo threshold not met, but stale).

Permissions Breakdown

  • search medium Can manipulate search provider; combined with newtab override raises monetization risk.
  • host_permissions: https://api.gameograf.com/* medium Scoped host access to external API endpoint; enables data exfil to gameograf.com.
  • chrome_url_overrides.newtab high NewTab override — high monetization/redirect surface, replaces browser new-tab page.

Pillar Scores

Permissions5.00
Reputation5.50
Network3.50
Webstore9.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 09:56
Listing SHA eeedc51ed59e…
Force block — not fired
Score recovered no
Elapsed