Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

HOT Wallet

mpeengabcnhhjjgleiodimegnkpcenbk
Risk Score
4.59
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 100,000
Rating 4.9
Last updated 2026-02-19 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@hot-labs.org
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host permissions (all HTTP/HTTPS) + scripting allow JS injection into every page including crypto exchanges — high-value target for seed-phrase theft.
  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — policy admits data sharing without scoping to this extension.
  • No CSP on MV3 extension; innerHTML sink in bundled styled-components elevates DOM-XSS risk across all visited pages.
  • No developer display name listed in store; reduces accountability for a financial/wallet extension handling private keys.
  • 12 external JS hosts contacted including onramp.money fiat on-ramp; third-party data flow from a wallet extension warrants scrutiny.

Evidence

  • broad_host_permissions manifest host_permissions http://*/* and https://*/* combined with scripting and content_scripts on all URLs.
  • privacy_policy_scope_mismatch crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admitting 3rd-party sharing.
  • no_csp manifest content_security_policy is null; no CSP protection for MV3 extension.
  • dom_xss_sink crx innerHTML user-controlled sink in styled-components.browser.esm; no CSP mitigates risk.
  • external_hosts_count crx 12 distinct external JS hosts including onramp.money, t.me, fonts.googleapis.com, api0.herewallet.app.
  • no_developer_name store developer_name is empty string; reduced accountability for a financial wallet extension.
  • install_count_reach store 100,000 installs; broad attack surface if extension is ever compromised or sold.
  • cve_findings_raw_empty crx No CVEs detected in bundled libraries; CVE pillar score 0.0.

Permissions Breakdown

  • storage low Standard wallet key/preference storage.
  • unlimitedStorage low Extended local storage for blockchain data; expected for wallet.
  • tabs medium Can read tab URLs and navigate; moderate surveillance surface.
  • activeTab medium Access to active page on user gesture; limited scope.
  • sidePanel low UI surface only; no data access by itself.
  • contextMenus low Adds right-click menu items; low risk.
  • scripting medium Can inject JS into pages; combined with broad host access this is significant.
  • http://*/* high Broad host permission enabling content-script and scripting injection on all HTTP sites.
  • https://*/* high Broad host permission on all HTTPS sites; covers banking, crypto exchanges, etc.

Pillar Scores

Permissions5.50
Reputation6.00
Network4.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 53899062ee06…
Force block — not fired
Score recovered no
Elapsed 26.6s