Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spotify artist's all songs

jdicfniianljldbajoghhnilmnghgmno
Risk Score
4.82
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 7,000
Rating 4.1
Last updated 2026-04-26 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer xdpugachevx@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Spotify brand impersonation by gmail developer with no verified identity or business domain.
  • Privacy policy is generic Google account policy — does not scope to this extension; admits data collection and 3rd-party sharing.
  • Three host permissions on unverified dev-controlled *.spotify-artists-all-songs.xyz subdomain cluster enable data exfiltration.
  • Free-webmail developer (gmail) with no business website or verified publisher badge raises accountability gap.
  • Sentry + PostHog telemetry bundled via sourcemaps; usage policy opaque given inadequate privacy policy.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands=['spotify'], confirmed_owner=false, dev domain=gmail.com
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true
  • unverified_dev_domain_host_perms manifest 3 host_permissions on *.spotify-artists-all-songs.xyz under gmail dev control
  • free_webmail_developer store developer_email=xdpugachevx@gmail.com; no business website; not verified publisher
  • telemetry_libraries crx Sentry and PostHog detected via sourcemaps in service-worker.js; versions unknown
  • featured_by_google store is_featured_by_google=true; partial trust signal but doesn't override brand impersonation or privacy gap
  • no_bad_hosts_or_affiliates api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no active malicious infra detected
  • cve_none crx cve_findings_raw empty; no CVE exposure from bundled libraries

Permissions Breakdown

  • storage low Persists extension state locally; minimal risk alone.
  • identity medium Can obtain OAuth tokens; used for Spotify auth but grants access to user identity.
  • tabs medium Can read tab URLs/titles; moderate reach over browsing context.
  • host: *://api.spotify-artists-all-songs.xyz/ high Third-party domain controlled by individual gmail dev; not Spotify official. Data exfil risk.
  • host: *://s.spotify-artists-all-songs.xyz/ high Same throwaway-domain pattern; additional endpoint under unverified dev control.
  • host: *://p.spotify-artists-all-songs.xyz/ high Third sub-domain on same unverified domain; expands attack surface.
  • host: *://api.spotify.com/ medium Official Spotify API; expected for stated function.
  • host: https://accounts.spotify.com/authorize low OAuth authorization endpoint; expected for login flow.

Pillar Scores

Permissions2.90
Reputation8.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA d965ad731eaa…
Force block — not fired
Score recovered no
Elapsed 23.2s