DeepSeek AI
lbpidmmacfagijehljcenlmmfieajamh
Risk Score
6.60
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation: uses 'DeepSeek' name but confirmed_owner=false and dev is free-webmail gmail account.
- Broad host permissions (http://*/* + https://*/*) + scripting allow full page read/write on every site visited.
- Privacy policy is Google's own generic policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- Install and uninstall URL hijacks to appfyl.com and Google Forms — monetization/tracking redirection pattern.
- Geo-diverse JS hosts (CA/IN/RU/US) including two opaque Supabase backends increase exfiltration surface.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; confirmed_owner=false; dev is SupaExt@gmail.com, not DeepSeek.
- free_webmail_dev store Developer email SupaExt@gmail.com; no verified business domain; reputation floor applies.
- broad_host_permissions manifest host_permissions include http://*/* and https://*/* paired with scripting permission.
- install_url_hijack crx onInstalled opens https://appfyl.com/deepseekai — 3rd-party redirect on install.
- uninstall_url_hijack crx setUninstallURL points to https://forms.gle/i8nmkaw42KQc2JzC9 — 3rd-party on uninstall.
- generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- geo_diverse_js_hosts crx JS hosts span CA, IN, RU, US (4 countries); includes two opaque Supabase backends.
- dom_xss_sink crx popup.js assigns user-controlled variable to innerHTML — DOM-XSS risk in popup context.
Permissions Breakdown
- storage low Local key-value store; low sensitivity alone.
- sidePanel low UI surface only; no data access on its own.
- identity medium Can request OAuth tokens; scope unclear without explicit OAuth scopes.
- activeTab medium Access to current tab DOM/URL on user gesture; limited but real.
- scripting high Programmatic script injection into pages; high capability.
- https://qfjcjtsklspbzxszcwmf.supabase.co/* medium Outbound to supabase backend; possible data exfil vector.
- https://wcehjqcgyyvcumrcvyre.supabase.co/* medium Second supabase backend; dual-backend raises monitoring concern.
- http://*/* high Broad HTTP host access — all non-HTTPS sites reachable.
- https://*/* high Broad HTTPS host access — all sites reachable.
Pillar Scores
Permissions7.50
Reputation8.50
Network5.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| fsssiedxn2f89c03cza"n2f89c03czsssiedx | 5.48 | Medium | review | 2026-09-02 |
| sssiedn888e9ceedp727562726963xsx | 5.24 | Medium | review | 2026-09-02 |
| v3.6 | 6.60 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA
04d029b0eb63…
Force block
— not fired
Score recovered
no
Elapsed
44.3s