Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Game Kittygram Pro

ialiakkbglbihgmbgeaoelcinpbhlilh
Risk Score
5.32
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 5
Rating
Last updated 2025-09-22 (12 months ago)
Manifest version MV3
CSP present ✅ yes
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack + install URL hijack flagged: classic low-quality monetization shell pattern
  • Privacy policy hosted on CDN subdomain (cdn.cloudapi.stream), scope_extension=false, data_collection=true — inadequate
  • 3 medium-severity jQuery CVEs (3.2.1 < 3.5.0 fixed_in) bundled in extension
  • 7 external JS hosts contacted including obscure CDN and dev-unknown domains; no permissions but sandbox allows unsafe-eval/unsafe-inline
  • Developer is free-webmail gmail, no developer name listed, very low install count (5) — accountability near zero

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hijacks detected; install opens popup/index.html — game-portal shell fingerprint.
  • js_external_hosts crx 7 external hosts: bnjmnt4n.now.sh, cdn.cloudapi.stream, cloudapi.stream, createjs.com, hammerjs.github.io, mths.be, www.opensource.org.
  • sandbox CSP unsafe-eval + unsafe-inline manifest sandbox CSP allows unsafe-inline and unsafe-eval on script-src; amplifies jQuery XSS CVE risk surface.
  • jquery CVEs crx jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • privacy policy inadequate store Policy hosted on CDN, not dev domain; scope_extension=false, data_collection=true, no retention, third_party_silence=true.
  • developer identity store Free webmail developer (gmail), no developer name, 5 installs — zero accountability.
  • verified_publisher claimed store verified_publisher=true but no dev name, gmail only, CDN-hosted privacy policy on cloudapi.stream.
  • months_since_update=12 store 12 months since update — 6-12 month stale band; jQuery CVEs unpatched throughout.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Pillar Scores

Permissions3.00
Reputation6.50
Network3.50
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:55
Listing SHA 412019d361f3…
Force block — not fired
Score recovered no
Elapsed