Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Squid Game Cursor - Custom Korean Drama Cursor for Chrome

kdnnogfmhpppncphlnecbdhoggpmbkci
Risk Score
6.57
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 108
Rating
Last updated 2025-06-06 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer heroking15@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack routes to tabplugins.com — third-party traffic monetization pattern.
  • Install URL hijack opens tabplugins.com on install — onInstalled redirect to 3rd party.
  • Privacy policy is Google's own policy (unscoped); extension collects data under undisclosed terms.
  • scripting + *://*/* grants full page read/write on every site for a cursor theme extension.
  • Free-webmail developer (gmail), no verified publisher, no business domain — unaccountable operator.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://tabplugins.com/cursors/ (3rd-party monetization site).
  • install_url_hijack crx onInstalled opens https://tabplugins.com/squid-game-cursor/ — 3rd-party redirect on install.
  • broad_host_scripting manifest host_permissions + content_scripts_matches both *://*/* with scripting permission — all sites.
  • privacy_policy_unscoped store Policy URL is Google's generic account policy; scope_extension=false, data_collection=true, 3rd_party_sharing=true.
  • free_webmail_dev store Developer email heroking15@gmail.com; no business domain; unverified publisher.
  • dom_sink_innerhtml crx innerHTML sink in main.4964ab1e.js; no CSP present — elevated DOM-XSS risk.
  • install_perm_anomaly api Only 108 installs with high-tier permissions (scripting + *://*/*) — tail attack surface.
  • maintenance_stale store 14 months since last update; 6-12mo band applies (+3.5).

Permissions Breakdown

  • storage low Standard local state persistence; low standalone risk.
  • unlimitedStorage low Allows large local storage; minor risk alone.
  • scripting high Paired with *://*/* host permission — can inject JS into every page.
  • *://*/* high Broad host access; scripting+all_urls enables full page content read/write.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:52
Listing SHA 242dbd909818…
Force block — not fired
Score recovered no
Elapsed