Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Earth Satellite

nhioomapcdomjekmegdnnlbcnjgnodon
Risk Score
6.48
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 40,000
Rating 1.2
Last updated 2026-06-29 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@qwerpdf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search provider overridden to g-maps.com — all user searches hijacked through attacker-controlled domain.
  • Uninstall and install URL hijacks both active — classic traffic-monetization shell pattern.
  • Privacy policy collected on g-maps.com (not qwerpdf.com), admits data collection + third-party sharing, zero extension scope.
  • Rating 1.2 on 40K installs strongly indicates user complaints about unwanted search redirection.
  • Developer email domain (qwerpdf.com) mismatches privacy policy domain (g-maps.com) — accountability gap.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default:true, routing all searches to g-maps.com/earth-satellite.php
  • uninstall_url_hijack crx uninstall_url_hijack=true; classic monetization shell — captures uninstall event for ad-tech redirect.
  • install_url_hijack crx install_url_hijack=true; opens 3rd-party URL on install — monetization onboarding pattern.
  • privacy_policy_scope_mismatch store Policy on g-maps.com, not dev domain; scope_extension=false, data_collection=true, third_party_sharing=true.
  • low_rating store Rating 1.2 on ~40K installs — consistent with user reports of search hijacking.
  • js_external_host crx Extension contacts g-maps.com — same domain as hijacked search provider.
  • name_function_mismatch store Extension named 'Earth Satellite' but primary function is search-provider override — cloaking pattern.
  • dev_domain_policy_domain_split store Developer qwerpdf.com, privacy policy hosted at g-maps.com — split accountability, no governance.

Permissions Breakdown

  • storage low Local data persistence only; low inherent risk.
  • chrome_settings_overrides.search_provider (is_default:true) high Forces default search engine to g-maps.com; classic search-hijack pattern.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:33
Listing SHA 13a255372c01…
Force block — not fired
Score recovered no
Elapsed