Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Darktheme for google translate

nmcamjpjiefpjagnjmkedchjkmedadhc
Risk Score
4.30
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Other
Installs 60,000
Rating 3.8
Last updated 2025-02-18 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer kohl.rainer1991@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to inst.darkmode.site — classic monetization/tracking redirect shell pattern (+3.0 webstore).
  • Install URL hijack to inst.darkmode.site — phoning home on install to third-party domain (+2.0 webstore).
  • Privacy policy is Google's own generic policy — does not scope to this extension; admits data collection and 3rd-party sharing → +10.0 privacy.
  • Brand impersonation: dev is unverified Gmail user citing Google brand without ownership confirmation (+2.0 reputation).
  • Free-webmail developer (gmail) with no business domain; free-webmail floor applied (reputation ≥ 7.5).

Evidence

  • uninstall_url_hijack crx setUninstallURL → https://inst.darkmode.site/uninstall.html; third-party domain, monetization/tracking signal.
  • install_url_hijack crx onInstalled opens https://inst.darkmode.site/install.html; third-party phone-home on install.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true; dev domain gmail.com, confirmed_owner=false, not verified publisher.
  • free_webmail_developer store Developer email kohl.rainer1991@gmail.com; no business website; reputation floor ≥ 7.5 applied.
  • dom_sink_innerhtml crx innerHTML sink in popup.100f6462.js; no CSP present → DOM-XSS risk elevated.
  • js_external_hosts crx Extension contacts inst.darkmode.site and reactjs.org externally; 2 non-primary external domains.
  • maintenance_stale store months_since_update=18; maintenance pillar +6.0 (12-24mo band).

Permissions Breakdown

  • storage low Stores extension preferences locally; minimal risk.
  • scripting medium Can inject scripts into matched pages (all Google Translate TLDs).
  • content_scripts (translate.google.*/) low Scoped only to translate.google domains; matches stated function.

Pillar Scores

Permissions1.30
Reputation7.50
Network2.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:53
Listing SHA aa152531c858…
Force block — not fired
Score recovered no
Elapsed