Shopify Spy & Dropshipping - Koala Inspector
hjbfbllnfhppnhjdhhbmjabikmkfekgf
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3 with no CSP — amplified CVE pillar 7.0
- code_quality 8.0: script_src_dynamic + function_constructor + innerHTML sink across background and content scripts, no CSP
- Privacy policy fetched but scope_extension=false with data_collection+third_party_sharing=true → +10.0 privacy (D rule)
- <all_urls> host_permissions + content_scripts on all URLs gives full page read/write on every site visited
- Brand impersonation: brands_mentioned=[shopify], confirmed_owner=false → +2.0 reputation penalty
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); no CSP amplifier applied.
- code_quality_dynamic_script_and_function_constructor crx script_src_dynamic and function_constructor found in both background and content scripts; no CSP mitigates.
- privacy_policy_scope_mismatch store Policy fetched (106K chars) but scope_extension=false; admits data_collection+third_party_sharing → privacy=10.0.
- all_urls_host_permission manifest <all_urls> host_permissions + content_scripts_matches=[<all_urls>]: full access to every page.
- brand_impersonation_shopify store brand_mention.is_impersonation=true for Shopify; confirmed_owner=false; not a verified Shopify product.
- no_csp manifest content_security_policy=null on MV3 extension; amplifies CVE and innerHTML/dynamic-script risk.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partial reputation discount applied.
- developer_name_empty store developer_name is empty string; no human-readable publisher identity in listing.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- identity medium Can obtain user's Google identity token; combined with email scope raises account-linkage risk.
- identity.email medium Explicitly requests user email address via OAuth identity API.
- <all_urls> (host_permissions) high Content scripts injected on every site; broad read/write access to all page content.
- tabs medium Can read tab URLs, titles, and navigation state across all open tabs.
- activeTab low Scoped to current tab on user gesture; lower standalone risk.
- storage low Local key-value storage; low risk in isolation.
- unlimitedStorage low Removes storage quota cap; potential for large local data accumulation.
- alarms low Periodic wake-up scheduling; low risk alone.
- declarativeNetRequest medium Can modify/block network requests; less risky than webRequest but still significant.
- declarativeNetRequestFeedback low Read-only feedback on matched rules; low incremental risk.
- contextMenus low Adds right-click menu items; minimal risk.
Pillar Scores
Permissions6.00
Reputation3.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality8.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
0dd11d791abe…
Force block
— not fired
Score recovered
no
Elapsed
38.4s