MERLIN BOT
jkblcpmoooocmdcfjojdecccejlkicap
Risk Score
6.16
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Operator cluster of 16 sibling extensions under same dev email — mass-deployment factory pattern.
- Uninstall URL hijack + install URL hijack flagged; typical monetization/surveillance shell tactic.
- Privacy policy is Google's own policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-specific disclosure.
- WhatsApp brand impersonation by unverified developer (extensao.store); no confirmed ownership.
- 10+ external JS hosts (wascript.com.br, watools.com.br) with no CSP; function_constructor and DOM-XSS sink in 334 JS files.
Evidence
- operator_cluster_siblings api 16 sibling extensions share identical dev email, install URL, and host set — factory-pattern deployment.
- uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true targeting https://web.whatsapp.com — redirect abuse.
- generic_privacy_policy store PP URL is Google's own policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation store WhatsApp brand mentioned; developer extensao.store is not confirmed owner; is_impersonation=true.
- external_js_hosts crx 10 distinct external hosts under wascript.com.br / watools.com.br; no CSP to restrict loading.
- function_constructor crx new Function() constructor found in JS file — arbitrary code execution risk.
- dom_xss_sink crx innerHTML assigned from variable without CSP; DOM-XSS risk on WhatsApp Web.
- no_csp crx content_security_policy is null; no script-src restrictions for MV3 extension with 334 JS files.
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low direct harm but supports large data caching.
- storage low Standard local key-value storage, low risk.
- alarms low Scheduled task execution; low risk alone.
- tabs medium Can read tab URLs and titles across sessions; moderate risk.
- https://web.whatsapp.com/* medium Host permission on WhatsApp Web allows content injection and data access within that site.
Pillar Scores
Permissions2.30
Reputation6.50
Network3.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Operator Siblings (24)
Other extensions sharing this developer's compound fingerprint:
- cellckcnenolgakggljkichbmgmbibgb
- aocojboaoklgedadlpaallelnanhcpgm
- bgnkgembgfkfjipflkniiibgcedloekn
- bjhbgbfapjofmjcoonncefneakppmkmo
- bpgbjcgkegcecddlnlckjcoddhpmekdh
- cplaeebopfpnoebkaimlibpdickcjofa
- afdhcpnimkgccfjcelgkiipidhebddjh
- abkolnpebgghiglkkdjcgjgbpnddmfmp
- gjlfpggiddcminhebiejofeglfjmleli
- gkkkdobapmhkaihggejlcdbjemfkhdgk
- gollbfedpcfodjgfjddbkfnkkfdedknn
- hcbmcbkjjklkjidikpggmmfpfklcpnmb
- hkdbocoaofpdmbbgpimdkhcafenpkikn
- iibldfhmeiipohbjlkhfgnjhcmkknffi
- ikliliinakofoiojghnipegfphmoljla
- jeicljefnlpdoblklfdephbpihhjgphf
- jhokpeoaapahcoaigkfnienliabeaang
- jcjodbceolndbhnbljiedcanmglmhmop
- lfenojckeamfnllggndghkmfhkheiimc
- ngnffiapbonmlgijfnlcgbdomhgcmmna
- lhadifphljjldcidjbhdpfcoemhddeec
- hdagfineacponepnaljjkkgjoddgpjld
- dkgcodmnjmlmgmdlbekkcjjjidkflnal
- hpfmfjmhhkfpcedjikogphkfacokfagh
Scoring History
| sssiedn0a1b7909dp727562726963xsx | 6.48 | High | block | 2026-09-07 |
| v3.6 | 6.16 | High | block | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:11
Listing SHA
817b6a28b36f…
Force block
— not fired
Score recovered
no
Elapsed
—