Labubu Sunbathing on the Beach
kgfigoaadlggpekffbfgfjkcljhnhnlh
Risk Score
5.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10 privacy).
- Uninstall URL hijack to gameograf.com UTM link and install URL hijack — classic monetization shell signals.
- NewTab override + search permission = high-reach monetization surface on every new tab opened.
- No CSP (csp_present=false) with innerHTML DOM-XSS sinks in popup.js and calendar.js elevates XSS risk.
- Rating of 1 and no developer name listed reduces accountability.
Evidence
- uninstall_url_hijack manifest setUninstallURL targets https://gameograf.com/?utm_source=gameograf — 3rd-party redirect on uninstall.
- install_url_hijack manifest onInstalled opens https://gameograf.com/?utm_source=install — monetization redirect on install.
- newtab_override manifest chrome_url_overrides.newtab = newtab.html; replaces every new tab for all users.
- generic_privacy_policy store Privacy URL is Google's global policy (myaccount.google.com/privacypolicy); scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_xss_sink_no_csp crx innerHTML from variable in popup.js and calendar.js with csp_present=false — DOM-XSS risk unmitigated.
- low_rating store Rating=1.0; no developer name provided; 358 installs — low accountability.
- verified_publisher store verified_publisher=true for gameograf.com; domain resolves, looks_throwaway=false — partial credit.
- no_developer_name store developer_name is empty string; reduces accountability signal.
Permissions Breakdown
- search medium Can manipulate search provider; paired with newtab override amplifies monetization risk.
- chrome_url_overrides.newtab medium Replaces every new tab — high-reach surface for ad/redirect monetization.
- host_permissions: https://api.gameograf.com/* low Scoped to dev's own API domain; limited blast radius.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:43
Listing SHA
b6a48209aedf…
Force block
— not fired
Score recovered
no
Elapsed
—