Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

KuCoin:Bitcoin,Dogecoin Price Market

nalaeminfbmmidadoaegigajbapfajgi
Risk Score
5.68
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 10,000
Rating 4.9
Last updated 2025-06-11 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer frontend@kupotech.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); no CSP amplifies risk.
  • Privacy policy is KuCoin's generic corporate policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
  • new Function() constructor in background.bundle.js paired with no CSP enables dynamic code execution.
  • Developer domain kupotech.com does not match KuCoin brand (kucoin.com); unverified publisher claiming KuCoin brand.
  • scripting + cookies permissions over kucoin.com with no CSP allows script injection and session cookie access on financial platform.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 carries CVE-2021-23358 (ACE, critical); fixed in 1.12.1. No CSP present — CVE amplifier ×1.5 applies.
  • no_csp_mv3 manifest content_security_policy is null; no CSP on MV3 extension with DOM sinks and vulnerable libs.
  • privacy_policy_generic store Policy is kucoin.com corporate page; scope_extension=false, data_collection=true, third_party_sharing=true — Privacy=10.0.
  • brand_domain_mismatch store Developer listed as 'KuCoin' but email is frontend@kupotech.com; not verified publisher; brand authenticity unconfirmed.
  • function_constructor crx new Function() in background.bundle.js with no CSP allows dynamic code execution.
  • innerhtml_sink_no_csp crx innerHTML from variable in popup.bundle.js; no CSP to mitigate DOM-XSS.
  • maintenance_12mo store Last updated June 2025 (~12 months ago); stale library versions not patched.
  • featured_by_google store is_featured_by_google=true; provides partial reputation credit but does not override CVE/privacy findings.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Scoped to user-initiated action on current tab only.
  • storage low Local data persistence; low risk standalone.
  • cookies high Can read/write cookies; risk elevated without <all_urls> but host_permissions cover kucoin.com.
  • tabs medium Can enumerate open tabs and their URLs.
  • declarativeNetRequest medium Can block/redirect network requests via static rules.
  • scripting high Can inject scripts into pages; broad capability even with narrow host perms.
  • alarms low Periodic background tasks; low risk standalone.
  • *://*.kucoin.com/* high Host permission scoped to kucoin.com; enables cookies+scripting on that domain.

Pillar Scores

Permissions5.50
Reputation5.00
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 2bb6376bce35…
Force block — not fired
Score recovered no
Elapsed 29.0s