Agência do Vale
hpfmfjmhhkfpcedjikogphkfacokfagh
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 24+ siblings under same developer email — mass-deployment factory pattern with high supply-chain risk.
- Privacy policy is Google's generic policy, not scoped to this extension; admits data collection and third-party sharing — worst-case privacy disclosure.
- Uninstall URL hijack and install URL hijack both present — active monetization/tracking shell patterns.
- WhatsApp brand impersonation by unverified developer with 10 external wascript.com.br backend hosts exposed to WhatsApp Web sessions.
- function_constructor (new Function) used across 4+ files with no CSP — dynamic code execution without sandbox on WhatsApp chat content.
Evidence
- operator_cluster_siblings api 24 sibling extensions share same developer email/fingerprint — factory-pattern mass deployment.
- uninstall_url_hijack+install_url_hijack crx Both onInstalled and uninstall URL hooks present — monetization/tracking shell pattern.
- generic_privacy_policy store Privacy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) triggers +10.
- brand_impersonation store WhatsApp brand mentioned; developer not confirmed owner (extensao.store) — +2.0 reputation.
- external_hosts_wascript crx 10 external wascript.com.br/watools.com.br endpoints contacted from WhatsApp Web content script context.
- function_constructor_no_csp crx new Function() in 4 files; csp_present=false; enables dynamic code execution without policy guard.
- dom_sink_innerhtml_no_csp crx innerHTML from variable + no CSP → DOM-XSS risk elevated to +2.0 per FIX B.
- no_verified_publisher store Not verified, not featured; developer email on extensao.store (992 days old, 59 certs).
Permissions Breakdown
- unlimitedStorage low Allows unbounded local storage; low direct harm but enables large local data retention.
- storage low Standard key-value storage; minimal risk alone.
- alarms low Scheduled execution; low risk on its own.
- tabs medium Can read URLs/titles of all open tabs; moderate privacy surface.
- https://web.whatsapp.com/* medium Scoped host access to WhatsApp Web; enables reading/modifying chat content.
Pillar Scores
Permissions2.30
Reputation7.50
Network4.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 07:50
Listing SHA
9aae6af27b3b…
Force block
— not fired
Score recovered
no
Elapsed
—