KuCoin:Bitcoin,Dogecoin Price Market
nalaeminfbmmidadoaegigajbapfajgi
Risk Score
5.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); no CSP amplifies risk.
- Privacy policy is KuCoin's generic corporate policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
- new Function() constructor in background.bundle.js paired with no CSP enables dynamic code execution.
- Developer domain kupotech.com does not match KuCoin brand (kucoin.com); unverified publisher claiming KuCoin brand.
- scripting + cookies permissions over kucoin.com with no CSP allows script injection and session cookie access on financial platform.
Evidence
- critical_cve_underscore crx underscore@1.8.3 carries CVE-2021-23358 (ACE, critical); fixed in 1.12.1. No CSP present — CVE amplifier ×1.5 applies.
- no_csp_mv3 manifest content_security_policy is null; no CSP on MV3 extension with DOM sinks and vulnerable libs.
- privacy_policy_generic store Policy is kucoin.com corporate page; scope_extension=false, data_collection=true, third_party_sharing=true — Privacy=10.0.
- brand_domain_mismatch store Developer listed as 'KuCoin' but email is frontend@kupotech.com; not verified publisher; brand authenticity unconfirmed.
- function_constructor crx new Function() in background.bundle.js with no CSP allows dynamic code execution.
- innerhtml_sink_no_csp crx innerHTML from variable in popup.bundle.js; no CSP to mitigate DOM-XSS.
- maintenance_12mo store Last updated June 2025 (~12 months ago); stale library versions not patched.
- featured_by_google store is_featured_by_google=true; provides partial reputation credit but does not override CVE/privacy findings.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Scoped to user-initiated action on current tab only.
- storage low Local data persistence; low risk standalone.
- cookies high Can read/write cookies; risk elevated without <all_urls> but host_permissions cover kucoin.com.
- tabs medium Can enumerate open tabs and their URLs.
- declarativeNetRequest medium Can block/redirect network requests via static rules.
- scripting high Can inject scripts into pages; broad capability even with narrow host perms.
- alarms low Periodic background tasks; low risk standalone.
- *://*.kucoin.com/* high Host permission scoped to kucoin.com; enables cookies+scripting on that domain.
Pillar Scores
Permissions5.50
Reputation5.00
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
2bb6376bce35…
Force block
— not fired
Score recovered
no
Elapsed
29.0s