Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spotify Web Player Search

klbmallgiemiofpknobjmpbpjndphedc
Risk Score
5.39
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 103
Rating 5.0
Last updated 2026-04-02 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer js8231437@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override routes all queries through chromecrxstore.com — classic search hijack with no affiliation to Spotify.
  • Spotify brand impersonation by gmail.com developer with no confirmed ownership; is_impersonation=true.
  • Privacy policy URL returned fetch error — effectively no accessible policy; pillar scores 10.
  • Free-webmail developer (js8231437@gmail.com), no developer name, no business domain — unverifiable identity.
  • Install URL hijack on install event; verified/featured badges despite brand impersonation and search hijack.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to chromecrxstore.com/query/index.html — not Spotify.
  • brand_impersonation store brand_mention.is_impersonation=true; developer domain gmail.com, confirmed_owner=false.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (HTTPError); policy inaccessible.
  • free_webmail_dev_no_name store developer_email=js8231437@gmail.com; developer_name empty; no business site.
  • install_url_hijack crx install_url_hijack=true; extension opens 3rd-party URL on install.
  • verified_featured_despite_hijack store verified_publisher=true and is_featured_by_google=true despite search override and brand impersonation.
  • suggest_url_third_party manifest suggest_url points to chromecrxstore.com/suggest.php — queries routed to unknown third party.
  • csp_absent_mv3 crx content_security_policy=null; MV3 default applies but no explicit CSP declared.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • host_permission: https://suggestqueries.google.com/ low Narrow host for autocomplete suggestions only.
  • chrome_settings_overrides.search_provider (is_default=true) medium Replaces default search engine with chromecrxstore.com — search hijack risk.

Pillar Scores

Permissions4.00
Reputation8.00
Network2.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:22
Listing SHA 14725844bbac…
Force block — not fired
Score recovered no
Elapsed