ZarpGo
jcjodbceolndbhnbljiedcanmglmhmop
Risk Score
6.36
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 19 sibling extensions under same fingerprint — mass-deployment of WhatsApp CRM shells.
- Privacy policy points to Google's own policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- 18 external wascript.com.br / watools.com.br API hosts contact backend infrastructure outside user control.
- WhatsApp brand impersonation: developer (extensao.store) is not a confirmed Meta/WhatsApp affiliate.
- Uninstall and install URL hijack active; function_constructor and innerHTML DOM-XSS sink present in code.
Evidence
- operator_cluster_siblings api 18 sibling extensions share same dev email, install URL, and JS host set — coordinated WhatsApp CRM shell cluster.
- privacy_policy_generic_google store Privacy policy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation store brands_mentioned=[whatsapp], confirmed_owner=false, is_impersonation=true; developer domain extensao.store not affiliated with Meta.
- uninstall_and_install_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true; install target https://web.whatsapp.com.
- js_external_hosts crx 10 distinct wascript.com.br and watools.com.br subdomains contacted; high outbound surface for a WhatsApp CRM tool.
- function_constructor crx new Function() constructor detected — dynamic code execution risk in content script.
- dom_sink_innerhtml crx innerHTML assigned from variable without CSP; DOM-XSS sink active on WhatsApp Web pages.
- no_csp manifest csp_present=false on MV3 extension contacting 10+ external hosts with dynamic code execution findings.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low direct risk but enables large data caching.
- storage low Standard local storage access; low risk.
- alarms low Schedules background tasks; low risk alone.
- tabs medium Can read tab URLs and titles; moderate risk, enables user activity tracking.
- https://web.whatsapp.com/* medium Host permission scoped to WhatsApp Web; allows content script injection and data read on all WhatsApp sessions.
Pillar Scores
Permissions2.30
Reputation7.50
Network4.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jkblcpmoooocmdcfjojdecccejlkicap
- jhokpeoaapahcoaigkfnienliabeaang
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:11
Listing SHA
c6a05ea700ac…
Force block
— not fired
Score recovered
no
Elapsed
—