Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

D2CHATPRO

hdagfineacponepnaljjkkgjoddgpjld
Risk Score
6.29
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs
Rating
Last updated 2026-09-04
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Operator cluster of 20 sibling extensions under same dev email — mass distribution shell pattern.
  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (→ +10 privacy).
  • Uninstall URL hijack and install URL hijack both active — traffic-monetization signals.
  • WhatsApp brand impersonation by unverified developer (extensao.store).
  • 10 external wascript.com.br / watools.com.br hosts contacted; no CSP; new Function() constructor found in code.

Evidence

  • operator_cluster_sibling_count_20 api 20 sibling extensions share same dev email, install URL, and CSP host set — mass shell pattern.
  • uninstall_and_install_url_hijack crx Both uninstall_url_hijack and install_url_hijack flagged true; install redirects to web.whatsapp.com.
  • privacy_policy_google_generic store PP URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true for 'whatsapp'; developer not confirmed owner of WhatsApp.
  • js_external_hosts_10_domains crx 10 external hosts all under wascript.com.br / watools.com.br; no CSP to constrain them.
  • function_constructor_found crx new Function() constructor in content JS; dynamic code execution risk on WhatsApp Web.
  • dom_xss_sink_innerhtml crx innerHTML assigned from variable with no CSP; DOM-XSS risk inside WhatsApp Web context.
  • no_csp_mv3 manifest csp_present=false; MV3 default CSP applies but external hosts and dynamic eval increase risk.

Permissions Breakdown

  • unlimitedStorage low Allows unlimited local storage; low standalone risk for a WhatsApp CRM.
  • storage low Standard key-value storage; low risk.
  • alarms low Scheduling alarms; benign for CRM reminders.
  • tabs medium Can enumerate open tabs and their URLs; moderate privacy surface.
  • https://web.whatsapp.com/* medium Host access to WhatsApp Web; enables content script injection into chat sessions.

Pillar Scores

Permissions2.00
Reputation7.00
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Scoring History

sssiedn5e380074dp727562726963xsx 6.19 High block 2026-09-07
v3.6 6.29 High block 2026-08-31

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 15:29
Listing SHA 7ededb0ee0de…
Force block — not fired
Score recovered no
Elapsed