Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DeepSeek AI

lbpidmmacfagijehljcenlmmfieajamh
Risk Score
6.60
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 9,000
Rating 4.2
Last updated 2026-09-01
Manifest version MV3
CSP present ✅ yes
Developer SupaExt@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'DeepSeek' name but confirmed_owner=false and dev is free-webmail gmail account.
  • Broad host permissions (http://*/* + https://*/*) + scripting allow full page read/write on every site visited.
  • Privacy policy is Google's own generic policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Install and uninstall URL hijacks to appfyl.com and Google Forms — monetization/tracking redirection pattern.
  • Geo-diverse JS hosts (CA/IN/RU/US) including two opaque Supabase backends increase exfiltration surface.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; confirmed_owner=false; dev is SupaExt@gmail.com, not DeepSeek.
  • free_webmail_dev store Developer email SupaExt@gmail.com; no verified business domain; reputation floor applies.
  • broad_host_permissions manifest host_permissions include http://*/* and https://*/* paired with scripting permission.
  • install_url_hijack crx onInstalled opens https://appfyl.com/deepseekai — 3rd-party redirect on install.
  • uninstall_url_hijack crx setUninstallURL points to https://forms.gle/i8nmkaw42KQc2JzC9 — 3rd-party on uninstall.
  • generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • geo_diverse_js_hosts crx JS hosts span CA, IN, RU, US (4 countries); includes two opaque Supabase backends.
  • dom_xss_sink crx popup.js assigns user-controlled variable to innerHTML — DOM-XSS risk in popup context.

Permissions Breakdown

  • storage low Local key-value store; low sensitivity alone.
  • sidePanel low UI surface only; no data access on its own.
  • identity medium Can request OAuth tokens; scope unclear without explicit OAuth scopes.
  • activeTab medium Access to current tab DOM/URL on user gesture; limited but real.
  • scripting high Programmatic script injection into pages; high capability.
  • https://qfjcjtsklspbzxszcwmf.supabase.co/* medium Outbound to supabase backend; possible data exfil vector.
  • https://wcehjqcgyyvcumrcvyre.supabase.co/* medium Second supabase backend; dual-backend raises monitoring concern.
  • http://*/* high Broad HTTP host access — all non-HTTPS sites reachable.
  • https://*/* high Broad HTTPS host access — all sites reachable.

Pillar Scores

Permissions7.50
Reputation8.50
Network5.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

fsssiedxn2f89c03cza"n2f89c03czsssiedx 5.48 Medium review 2026-09-02
sssiedn888e9ceedp727562726963xsx 5.24 Medium review 2026-09-02
v3.6 6.60 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA 04d029b0eb63…
Force block — not fired
Score recovered no
Elapsed 44.3s