Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Product Scraper | 10X

mnacfoefejolpobogooghoclppjcgfcm
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 23
Rating 5.0
Last updated 2025-12-10 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer 10xprofitio@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores maximum privacy risk.
  • Gmail developer email with no verified publisher; brand_mention flags Amazon impersonation.
  • Content scripts injected across 20+ Amazon regional domains; scraped data sent to unknown ecomstal.com crawler endpoints.
  • No CSP (csp_present=false, MV3) combined with innerHTML DOM-XSS sink in main.js.
  • Hosts span 3 countries (CN, IE, US) including China-geolocated infrastructure for a scraper tool.

Evidence

  • privacy_policy_admits_3p_sharing_not_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D applies: +10.0 privacy.
  • brand_impersonation_amazon store brand_mention.is_impersonation=true, confirmed_owner=false, developer_domain=gmail.com.
  • third_party_crawler_hosts manifest Host perms include searchcrwler-a/b.ecomstal.com — unknown crawler infra receiving Amazon scraped data.
  • free_webmail_dev_no_verified_publisher store Developer email 10xprofitio@gmail.com; verified_publisher=false; is_featured_by_google=false.
  • dom_xss_sink_no_csp crx innerHTML user-controlled sink in main.js with csp_present=false raises XSS risk.
  • geo_diversity_cn_ie_us crx JS external hosts span 3 countries including CN; not VPN/translation category.
  • operator_cluster_dev_email_siblings api dev_email dimension sibling_count=2 indicates same gmail account owns other extensions.
  • tos_violation_amazon_scraper store Extension explicitly scrapes Amazon product data to CSV — violates Amazon ToS (v3.1 rule 7).

Permissions Breakdown

  • activeTab low Grants access only to currently active tab on user action; limited scope.
  • storage low Local data persistence; low standalone risk.
  • scripting medium Allows programmatic script injection into pages; elevated with host permissions.
  • *://*.amazon.com/* (and 20+ amazon domains) high Broad host access across all Amazon regional domains enables scraping/reading all page content.
  • https://searchcrwler-a.ecomstal.com/* + https://searchcrwler-b.ecomstal.com/* high Unknown third-party crawler service; data may be exfiltrated there.
  • https://app.10xprofit.io/* medium Developer backend; scraped data likely sent here.
  • http://localhost:3000/* low Localhost access — likely dev artifact; low external risk.

Pillar Scores

Permissions4.50
Reputation7.50
Network4.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:21
Listing SHA 309c0e4fae48…
Force block — not fired
Score recovered no
Elapsed