Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MERLIN BOT

jkblcpmoooocmdcfjojdecccejlkicap
Risk Score
6.16
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 16
Rating 5.0
Last updated 2026-09-04
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Operator cluster of 16 sibling extensions under same dev email — mass-deployment factory pattern.
  • Uninstall URL hijack + install URL hijack flagged; typical monetization/surveillance shell tactic.
  • Privacy policy is Google's own policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-specific disclosure.
  • WhatsApp brand impersonation by unverified developer (extensao.store); no confirmed ownership.
  • 10+ external JS hosts (wascript.com.br, watools.com.br) with no CSP; function_constructor and DOM-XSS sink in 334 JS files.

Evidence

  • operator_cluster_siblings api 16 sibling extensions share identical dev email, install URL, and host set — factory-pattern deployment.
  • uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true targeting https://web.whatsapp.com — redirect abuse.
  • generic_privacy_policy store PP URL is Google's own policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
  • brand_impersonation store WhatsApp brand mentioned; developer extensao.store is not confirmed owner; is_impersonation=true.
  • external_js_hosts crx 10 distinct external hosts under wascript.com.br / watools.com.br; no CSP to restrict loading.
  • function_constructor crx new Function() constructor found in JS file — arbitrary code execution risk.
  • dom_xss_sink crx innerHTML assigned from variable without CSP; DOM-XSS risk on WhatsApp Web.
  • no_csp crx content_security_policy is null; no script-src restrictions for MV3 extension with 334 JS files.

Permissions Breakdown

  • unlimitedStorage low Allows unlimited local storage; low direct harm but supports large data caching.
  • storage low Standard local key-value storage, low risk.
  • alarms low Scheduled task execution; low risk alone.
  • tabs medium Can read tab URLs and titles across sessions; moderate risk.
  • https://web.whatsapp.com/* medium Host permission on WhatsApp Web allows content injection and data access within that site.

Pillar Scores

Permissions2.30
Reputation6.50
Network3.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

sssiedn0a1b7909dp727562726963xsx 6.48 High block 2026-09-07
v3.6 6.16 High block 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:11
Listing SHA 817b6a28b36f…
Force block — not fired
Score recovered no
Elapsed