Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TeleStream Saver – Telegram Private Media Downloader

mandphkkkoolljjbpabjcinekbjmgbbm
Risk Score
4.38
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 10,000
Rating 3.8
Last updated 2026-06-14
Manifest version MV3
CSP present ❌ no
Developer chrome@vastflow.kz
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack sends users to 3rd-party Google Form — classic feedback/tracking redirect.
  • Brand impersonation of Telegram (unverified owner) elevates reputation risk significantly.
  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true — policy admits data sharing without scoping to this extension, triggering max privacy score.
  • Content scripts injected into all Telegram web clients can read private messages and media without 'downloads' permission declared (description mismatch).
  • No CSP on MV3 extension with host access to sensitive Telegram domains.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL points to docs.google.com Google Form — 3rd-party redirect on uninstall.
  • brand_impersonation store brand_mention.is_impersonation=true for 'telegram'; developer is not confirmed owner.
  • privacy_policy_generic_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing, not scoped to extension.
  • description_permission_mismatch store Promises 'download' functionality but lacks 'downloads' permission in manifest.
  • no_developer_name store developer_name is empty string; only email chrome@vastflow.kz available.
  • content_scripts_telegram crx Content scripts injected into all 4 Telegram web domains; can access private chat DOM and media.
  • no_csp crx content_security_policy is null; no CSP declared for MV3 extension.
  • v3_7_tos_violation store MediaDownloader targeting Telegram private media — likely ToS violation for Telegram platform scraping.

Permissions Breakdown

  • storage low Stores local settings/state; minimal risk on its own.
  • host: https://web.telegram.org/* medium Content-script access to Telegram web; can read private messages/media in-page.
  • host: https://webk.telegram.org/* medium Same as above — Telegram K-client variant.
  • host: https://web.telegram.org/a/* medium Telegram A-client subpath; overlapping sensitive DOM access.
  • host: https://webz.telegram.org/* medium Telegram Z-client; read access to private chats and media.

Pillar Scores

Permissions2.50
Reputation7.00
Network0.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 37056ffc72fe…
Force block — not fired
Score recovered no
Elapsed 21.2s