Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify Spy & Dropshipping - Koala Inspector

hjbfbllnfhppnhjdhhbmjabikmkfekgf
Risk Score
4.43
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Shopping
Installs 200,000
Rating 4.7
Last updated 2026-06-11
Manifest version MV3
CSP present ❌ no
Developer hello@koala-apps.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3 with no CSP — amplified CVE pillar 7.0
  • code_quality 8.0: script_src_dynamic + function_constructor + innerHTML sink across background and content scripts, no CSP
  • Privacy policy fetched but scope_extension=false with data_collection+third_party_sharing=true → +10.0 privacy (D rule)
  • <all_urls> host_permissions + content_scripts on all URLs gives full page read/write on every site visited
  • Brand impersonation: brands_mentioned=[shopify], confirmed_owner=false → +2.0 reputation penalty

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); no CSP amplifier applied.
  • code_quality_dynamic_script_and_function_constructor crx script_src_dynamic and function_constructor found in both background and content scripts; no CSP mitigates.
  • privacy_policy_scope_mismatch store Policy fetched (106K chars) but scope_extension=false; admits data_collection+third_party_sharing → privacy=10.0.
  • all_urls_host_permission manifest <all_urls> host_permissions + content_scripts_matches=[<all_urls>]: full access to every page.
  • brand_impersonation_shopify store brand_mention.is_impersonation=true for Shopify; confirmed_owner=false; not a verified Shopify product.
  • no_csp manifest content_security_policy=null on MV3 extension; amplifies CVE and innerHTML/dynamic-script risk.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partial reputation discount applied.
  • developer_name_empty store developer_name is empty string; no human-readable publisher identity in listing.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • identity medium Can obtain user's Google identity token; combined with email scope raises account-linkage risk.
  • identity.email medium Explicitly requests user email address via OAuth identity API.
  • <all_urls> (host_permissions) high Content scripts injected on every site; broad read/write access to all page content.
  • tabs medium Can read tab URLs, titles, and navigation state across all open tabs.
  • activeTab low Scoped to current tab on user gesture; lower standalone risk.
  • storage low Local key-value storage; low risk in isolation.
  • unlimitedStorage low Removes storage quota cap; potential for large local data accumulation.
  • alarms low Periodic wake-up scheduling; low risk alone.
  • declarativeNetRequest medium Can modify/block network requests; less risky than webRequest but still significant.
  • declarativeNetRequestFeedback low Read-only feedback on matched rules; low incremental risk.
  • contextMenus low Adds right-click menu items; minimal risk.

Pillar Scores

Permissions6.00
Reputation3.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality8.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 0dd11d791abe…
Force block — not fired
Score recovered no
Elapsed 38.4s