Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Fronty Leads

lackhjbdjbnbbhbpoaloegokakncjfeg
Risk Score
5.24
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 36
Rating 4.0
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contato@extensao.store
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension, admits data collection and 3rd-party sharing (D rule: +10.0).
  • WhatsApp brand impersonation: developer domain extensao.store is not affiliated with Meta/WhatsApp.
  • Uninstall and install URL hijack both flagged; install redirects to web.whatsapp.com (obfuscates behavior).
  • 12 distinct external JS hosts under wascript.com.br / watools.com.br with no CSP — large remote attack surface.
  • function_constructor (new Function) and innerHTML DOM-XSS sink found in scanned JS files.

Evidence

  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection+third_party_sharing=true → +10.0 privacy.
  • brand_impersonation_whatsapp store brand_mention.is_impersonation=true for 'whatsapp'; developer domain extensao.store not verified → +2.0 reputation.
  • uninstall_and_install_url_hijack manifest uninstall_url_hijack=true, install_url_hijack=true (target: https://web.whatsapp.com) → +3.0+2.0 webstore.
  • external_js_hosts crx 12 distinct external JS hosts (wascript.com.br, watools.com.br etc.) with no CSP → high network reach.
  • code_function_constructor crx new Function() constructor found → +2.5 code quality (function_constructor signal).
  • code_innerhtml_no_csp crx innerHTML user-controlled sink with csp_present=false → +2.0 code quality (FIX B).
  • no_csp_mv3 manifest content_security_policy=null; MV3 so no +2.0 network penalty, but amplifies code findings.
  • developer_identity_weak store developer_name='wsll', no verified publisher, no featured badge; email on .store TLD → elevated reputation risk.

Permissions Breakdown

  • unlimitedStorage low Local storage only; no cross-origin data exfil on its own.
  • storage low Standard extension storage; low standalone risk.
  • alarms low Scheduling only; no data access.
  • tabs medium Can read tab URLs and titles; elevated when paired with WhatsApp host.
  • https://web.whatsapp.com/* medium Scoped to WhatsApp Web; content scripts can read messages and DOM.

Pillar Scores

Permissions2.30
Reputation7.00
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:36
Listing SHA 662dc95d0100…
Force block — not fired
Score recovered no
Elapsed