Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

FastStream Video Player

kkeakohpadmbldjaiggikmnldlfkdfog
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 70,000
Rating 4.7
Last updated 2026-03-18 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer andrews54757@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • userScripts permission + <all_urls>: arbitrary script injection into every visited page is extremely high-capability.
  • webRequest + <all_urls>: can observe/intercept all network traffic; amplifies risk of any future compromise.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection & 3rd-party sharing.
  • new Function() called with externally-supplied argNames/body in yt_runner.js; code-exec from message data.
  • Free-webmail dev (gmail), no verified business identity, no developer name listed in store.

Evidence

  • userScripts + <all_urls> manifest userScripts permission allows injecting arbitrary JS into all URLs; highest-risk capability combo in MV3.
  • webRequest + <all_urls> manifest webRequest paired with broad host access enables full traffic interception across all sites.
  • function_constructor in yt_runner.js crx new Function(event.data.argNames, event.data.body) executes attacker-controlled code from message events.
  • generic privacy policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free-webmail developer, no name store Developer email andrews54757@gmail.com; developer_name empty; no verified business domain.
  • verified_publisher + is_featured_by_google store Extension carries verified publisher and Featured badges — positive trust signal offsetting some reputation risk.
  • no bad_host / affiliate / monetization hits api Threat intel shows zero bad hosts, affiliate hits, or monetization endpoints.
  • CSP present, MV3, no obfuscation crx script-src 'self' wasm-unsafe-eval; no remote script loading; obfuscation_score=0.0.

Permissions Breakdown

  • storage low Stores extension settings locally; standard low-risk API.
  • tabs medium Can read tab URLs and titles across all tabs.
  • webRequest high Intercepts all network requests; high capability when paired with <all_urls>.
  • declarativeNetRequest medium Can block/redirect requests declaratively; scoped but still powerful.
  • userScripts high Allows injecting arbitrary user scripts into pages; significant code-execution surface.
  • <all_urls> (host_permission) high Grants content-script and request access to every URL the user visits.

Pillar Scores

Permissions6.50
Reputation5.00
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA 0abc459b41c8…
Force block — not fired
Score recovered no
Elapsed 23.8s