Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Sticky Notes

hkhmodcdjhcidbcncgmnknjppphcpgmh
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 6
Rating 5.0
Last updated 2026-02-17 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer 10xprofitio@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: developer (gmail) is not Amazon, confirmed non-owner, extension uses Amazon branding.
  • Privacy policy admits data collection + third-party sharing with no extension-specific scope — worst-case policy.
  • Uninstall and install URL hijack flags set; onInstalled/onUninstalled open 3rd-party URLs.
  • Free-webmail dev (gmail) with no verified business identity; no verified publisher badge.
  • Content scripts run on 23 Amazon domains globally, giving broad read access to shopping sessions.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer domain is gmail.com, confirmed_owner=false; extension named after Amazon.
  • install_url_hijack + uninstall_url_hijack crx Both install_url_hijack and uninstall_url_hijack are true; targets null but hooks registered.
  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D-rule +10.0.
  • free_webmail_developer store Developer email 10xprofitio@gmail.com; no verified publisher; no recognized org.
  • content_scripts_broad_amazon manifest Content scripts injected into 23 Amazon TLDs (*://*.amazon.*/*).
  • js_external_hosts crx Extension contacts 10xprofit.io and www.amazon.com externally; MV3 + no CSP.
  • very_low_installs store Only 6 installs; high-capability extension with near-zero user base raises tail-risk.
  • no_cve_no_obfuscation crx cve_findings_raw empty; obfuscation_score=0.0; code_findings_raw empty — code surface looks clean.

Permissions Breakdown

  • storage low Used to persist sticky notes locally; low risk on its own.
  • content_scripts (*://*.amazon.*/) medium Injects JS into all Amazon storefronts globally; can read page content and user data on those pages.

Pillar Scores

Permissions2.00
Reputation7.50
Network2.00
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:44
Listing SHA 1a5007861344…
Force block — not fired
Score recovered no
Elapsed