Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Jujutsu Infinite Script [♾️Spin+ KILL] (March 2025)

mnnnhjdoengpicjmnoldbdncnoheknhd
Risk Score
3.69
Risk Level: Low
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 207
Rating
Last updated 2025-03-04 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer gyanpariksha.in@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack AND install URL hijack both active — classic monetization/redirect shell pattern.
  • Privacy policy is Google's own policy (not extension-scoped), admits data collection and 3rd-party sharing — scores maximum privacy risk.
  • Free-webmail Gmail developer with no verified identity or business website.
  • Extension contacts external host yoki.games with no CSP, no declared permissions, and zero stated functionality justification.
  • Game-cheat/script shell with 17-month-stale update — abandoned low-integrity payload delivery vehicle.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hijacks active; targets null but hooks confirmed — classic traffic-monetization shell.
  • privacy_policy_generic_google store PP URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev store Developer email gyanpariksha.in@gmail.com; developer_domain resolves to gmail.com — no verified business entity.
  • external_js_host crx JS loaded from yoki.games — unknown third-party game portal with no CSP to restrict execution.
  • no_csp manifest content_security_policy is null; MV3 but no CSP means remote JS from yoki.games can execute unconstrained.
  • stale_maintenance store Last updated March 4 2025, months_since_update=17 — falls in 6-12mo stale band.
  • game_cheat_shell store Title advertises game scripts (Auto Farm, Infinite Spin, Kill Aura) — low-effort game-portal shell pattern.
  • privacy_policy_d_clause store PP fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) +10.0 privacy.

Pillar Scores

Permissions0.00
Reputation7.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:00
Listing SHA 2e7aa6bd0e94…
Force block — not fired
Score recovered no
Elapsed