Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Mercedes F1 Car Wallpaper

koafigpkecfmlgbkjmbhdldnjhiokjhf
Risk Score
5.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 1,000
Rating 5.0
Last updated 2026-06-18 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer nermincandas@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override (index.html) gives persistent control of every new tab; uninstall URL hijack to owhit.com confirms monetization intent.
  • Privacy policy is Google's own generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case v3.5D: +10 privacy pillar.
  • Install URL hijack to owhit.com on install opens 3rd-party page; combined with uninstall hijack signals traffic-monetization shell.
  • Free-webmail Gmail dev with no developer name and no business domain; verified_publisher badge does not remove accountability gap.
  • 8 external JS hosts including major platforms (YouTube, Netflix, Instagram, X) contacted by a wallpaper/newtab extension — scope mismatch.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab='index.html' — replaces all new tabs; +2.0 Webstore new-tab override with monetization shape.
  • uninstall_url_hijack crx setUninstallURL -> https://owhit.com/uninstall; +3.0 Webstore per rubric rule.
  • install_url_hijack crx onInstalled opens https://owhit.com/mercedes-f1-car-wallpaper; +2.0 Webstore per rubric rule.
  • privacy_policy_generic store Policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5D).
  • free_webmail_no_devname store developer_email=nermincandas@gmail.com, developer_name empty; +1.5 Reputation free-webmail, +1.0 no dev name.
  • js_external_hosts_scope_mismatch crx 8 external hosts (Netflix, Instagram, YouTube, X, ChatGPT etc.) for a wallpaper newtab extension — unexplained breadth.
  • verified_publisher store verified_publisher=true grants -3.0 Reputation; but monetization hits cap VP discount to -1.0 per v3.5E.
  • cve_findings_empty crx No CVE findings; jquery 3.7.1 is current and unvulnerable. CVE pillar = 0.0.

Permissions Breakdown

  • search medium Can override search provider behavior; medium-risk in context of newtab override.
  • chrome_url_overrides.newtab high Replaces every new tab page; high reach monetization surface, scored per v2 rule (a).

Pillar Scores

Permissions4.00
Reputation7.00
Network0.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 14:39
Listing SHA d49eeaf86d00…
Force block — not fired
Score recovered no
Elapsed