Game Kittygram Pro
ialiakkbglbihgmbgeaoelcinpbhlilh
Risk Score
5.32
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack + install URL hijack flagged: classic low-quality monetization shell pattern
- Privacy policy hosted on CDN subdomain (cdn.cloudapi.stream), scope_extension=false, data_collection=true — inadequate
- 3 medium-severity jQuery CVEs (3.2.1 < 3.5.0 fixed_in) bundled in extension
- 7 external JS hosts contacted including obscure CDN and dev-unknown domains; no permissions but sandbox allows unsafe-eval/unsafe-inline
- Developer is free-webmail gmail, no developer name listed, very low install count (5) — accountability near zero
Evidence
- uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hijacks detected; install opens popup/index.html — game-portal shell fingerprint.
- js_external_hosts crx 7 external hosts: bnjmnt4n.now.sh, cdn.cloudapi.stream, cloudapi.stream, createjs.com, hammerjs.github.io, mths.be, www.opensource.org.
- sandbox CSP unsafe-eval + unsafe-inline manifest sandbox CSP allows unsafe-inline and unsafe-eval on script-src; amplifies jQuery XSS CVE risk surface.
- jquery CVEs crx jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- privacy policy inadequate store Policy hosted on CDN, not dev domain; scope_extension=false, data_collection=true, no retention, third_party_silence=true.
- developer identity store Free webmail developer (gmail), no developer name, 5 installs — zero accountability.
- verified_publisher claimed store verified_publisher=true but no dev name, gmail only, CDN-hosted privacy policy on cloudapi.stream.
- months_since_update=12 store 12 months since update — 6-12 month stale band; jQuery CVEs unpatched throughout.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions3.00
Reputation6.50
Network3.50
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:55
Listing SHA
412019d361f3…
Force block
— not fired
Score recovered
no
Elapsed
—