Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Fallout Cursor - Custom Game Cursor for Chrome

igmblpicjfppdloljoabpiafdlokogno
Risk Score
7.63
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 414
Rating 4.5
Last updated 2026-04-22 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer mbilalshah0001@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension, admits data collection and 3rd-party sharing: +10.0 privacy pillar.
  • Uninstall URL hijack to tabplugins.com and install URL hijack to tabplugins.com — classic monetization shell signals.
  • scripting + *://*/*onfigure content scripts on every page: high-reach capability from a free-webmail developer with no stated developer name.
  • Free-webmail developer (mbilalshah0001@gmail.com), no developer name — reputation floor triggered.
  • small_install_high_perm anomaly (408 installs + broad host access) raises tail-attack-surface concern.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization site).
  • install_url_hijack crx onInstalled opens https://tabplugins.com/fallout-cursor-... (3rd-party redirect on install).
  • privacy_policy_generic store Policy is Google account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_devname store Developer email mbilalshah0001@gmail.com; developer_name empty; no business website verifiable.
  • host_permissions_broad manifest *://*/* combined with scripting permission allows JS injection into every site visited.
  • dom_sink_innerhtml crx innerHTML assigned from variable in main.4964ab1e.js — DOM-XSS sink with no CSP.
  • install_perm_anomaly api Only 408 installs but has HIGH-tier permission (scripting + *://*/*) — small_install_high_perm=true.
  • verified_publisher store verified_publisher=true; however no recognized org, free-webmail email, limits discount applicability.

Permissions Breakdown

  • storage low Standard local persistence; low standalone risk.
  • unlimitedStorage low Allows large local storage quota; low risk for cursor assets.
  • scripting high Can inject JS into all pages via host_permissions *://*/*; significant capability.
  • *://*/* (host_permissions) high Broad host access paired with scripting — can read/modify any page content.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn9fa64870dp727562726963xsx 6.24 High block 2026-08-30
v3.6 7.63 High block 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:48
Listing SHA 9df0e65cb4e9…
Force block — not fired
Score recovered no
Elapsed