Fallout Cursor - Custom Game Cursor for Chrome
igmblpicjfppdloljoabpiafdlokogno
Risk Score
7.63
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension, admits data collection and 3rd-party sharing: +10.0 privacy pillar.
- Uninstall URL hijack to tabplugins.com and install URL hijack to tabplugins.com — classic monetization shell signals.
- scripting + *://*/*onfigure content scripts on every page: high-reach capability from a free-webmail developer with no stated developer name.
- Free-webmail developer (mbilalshah0001@gmail.com), no developer name — reputation floor triggered.
- small_install_high_perm anomaly (408 installs + broad host access) raises tail-attack-surface concern.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization site).
- install_url_hijack crx onInstalled opens https://tabplugins.com/fallout-cursor-... (3rd-party redirect on install).
- privacy_policy_generic store Policy is Google account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_devname store Developer email mbilalshah0001@gmail.com; developer_name empty; no business website verifiable.
- host_permissions_broad manifest *://*/* combined with scripting permission allows JS injection into every site visited.
- dom_sink_innerhtml crx innerHTML assigned from variable in main.4964ab1e.js — DOM-XSS sink with no CSP.
- install_perm_anomaly api Only 408 installs but has HIGH-tier permission (scripting + *://*/*) — small_install_high_perm=true.
- verified_publisher store verified_publisher=true; however no recognized org, free-webmail email, limits discount applicability.
Permissions Breakdown
- storage low Standard local persistence; low standalone risk.
- unlimitedStorage low Allows large local storage quota; low risk for cursor assets.
- scripting high Can inject JS into all pages via host_permissions *://*/*; significant capability.
- *://*/* (host_permissions) high Broad host access paired with scripting — can read/modify any page content.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiedn9fa64870dp727562726963xsx | 6.24 | High | block | 2026-08-30 |
| v3.6 | 7.63 | High | block | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:48
Listing SHA
9df0e65cb4e9…
Force block
— not fired
Score recovered
no
Elapsed
—