Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Mass Downloader for Instagram – Safe Bulk Download

ijcemfcomjlamigapfebkgdgehbmjpjj
Risk Score
4.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 2,000
Rating 4.8
Last updated 2026-06-15
Manifest version MV3
CSP present ❌ no
Developer bigbeatricemelo@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Instagram brand impersonation: dev is gmail-only, confirmed_owner=false, capturing Instagram session cookies.
  • cookies + webRequest on instagram.com enables Instagram session credential harvesting.
  • No CSP and 3x innerHTML DOM-XSS sinks across content script, options, and popup.
  • Privacy policy admits data collection and third-party sharing without retention disclosure.
  • Free-webmail developer (gmail) with no verifiable business identity.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, developer_email is gmail; extension accesses instagram.com.
  • free_webmail_dev store developer_email=bigbeatricemelo@gmail.com; no business domain; verified_publisher=true but gmail-only identity.
  • high_risk_permissions_combo manifest cookies + webRequest + host_permissions instagram.com: session credential read/exfil capability.
  • no_csp crx content_security_policy=null on MV3 extension; DOM-XSS sinks present in 3 JS files.
  • dom_xss_sinks crx dom_sink_innerhtml_userctrl in 3 files (overlay, options, popup) with no CSP guard.
  • privacy_policy_gaps api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • igmate_backend_hosts manifest host_permissions include igmate.net and igmate.me; same domain as privacy policy; potential data exfil endpoints.
  • verified_publisher_caveat store verified_publisher=true but v3.5(E) caps discount: monetization/affiliate hits absent but gmail identity undermines trust.

Permissions Breakdown

  • storage low Standard local state storage; low risk.
  • alarms low Scheduling only; low risk.
  • downloads medium Can save files to user's disk; matches downloader category.
  • cookies high Can read/write cookies for instagram.com and igmate domains; session-theft risk.
  • webRequest high Observe all matching requests; combined with cookies raises credential exfil risk.
  • https://*.instagram.com/* high Full access to Instagram pages; combined with cookies+webRequest = high-value session surface.
  • https://igmate.net/* medium Dev-controlled backend; data may be sent there.
  • https://igmate.me/* medium Second dev-controlled domain; expands exfil surface.

Pillar Scores

Permissions6.00
Reputation7.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:20
Listing SHA 05fa1f33cc32…
Force block — not fired
Score recovered no
Elapsed 27.5s