Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Death Note Cursor - Custom Anime Cursor for Chrome

hdholjicmhinpjcbmigoffjedkiihlen
Risk Score
6.69
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 806
Rating 5.0
Last updated 2025-05-28 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer waqasamjad1232@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijacks redirect to tabplugins.com — confirmed monetization shell pattern.
  • Google's own privacy policy submitted as extension policy: admits data collection + 3rd-party sharing with no extension scope.
  • scripting + *://*/* allows arbitrary JS injection on every site the user visits.
  • Free-webmail dev (gmail), no developer name, no business website — unverifiable identity.
  • Small-install + high-perm anomaly and install_perm_anomaly flags both raised; tail attack surface risk.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party redirect).
  • install_url_hijack crx onInstalled opens https://tabplugins.com/death-note-cursor/ (3rd-party redirect).
  • privacy_policy_generic store Policy is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_devname store Dev email waqasamjad1232@gmail.com; developer_name empty; no business domain verifiable.
  • broad_host_scripting manifest scripting + host_permissions *://*/* enables JS injection on all sites; unjustified for cursor extension.
  • dom_sink_innerhtml crx innerHTML sink in main.4964ab1e.js with no CSP; DOM-XSS risk elevated.
  • install_perm_anomaly api 806 installs, HIGH-tier permissions — small_install_high_perm and tail_attack_surface both true.
  • stale_15mo store Last updated May 2025, 15 months since update; maintenance risk elevated (6-12mo band).

Permissions Breakdown

  • storage low Standard local data persistence; low risk on its own.
  • unlimitedStorage low Allows larger local storage quota; minimal risk for a cursor extension.
  • scripting high Combined with *://*/* host access allows arbitrary JS injection on all sites.
  • *://*/* high Broad host access; cursor extension has no justified need for all URLs.

Pillar Scores

Permissions7.00
Reputation7.00
Network4.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:42
Listing SHA acfc3f77a96f…
Force block — not fired
Score recovered no
Elapsed