Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Animal Crossing Cursor - Custom Nintendo Game Cursor for Chrome

nmkpckdpiikfoenhfaognmajhpgpoobg
Risk Score
5.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 300
Rating 2.0
Last updated 2026-06-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@tabplugins.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to google.com redirect wrapping tabplugins.com — classic monetization shell behaviour.
  • Install URL hijack opens tabplugins.com marketing page on every install.
  • scripting + *://*/* host access allows JS injection on every site the user visits.
  • Privacy policy admits data collection and third-party sharing without retention disclosure.
  • Cursor-theme extension with broad host permissions is a scope mismatch; 300 installs + high perms is tail-attack-surface anomaly.

Evidence

  • uninstall_url_hijack crx setUninstallURL targets google.com redirect wrapping tabplugins.com/cursors/ — monetization shell indicator.
  • install_url_hijack crx onInstalled opens tabplugins.com/animal-crossing-cursor/?utm_source=google — traffic monetization.
  • broad_host_access manifest host_permissions and content_scripts_matches both set to *://*/* on a cursor-theme extension.
  • privacy_policy_deficiency store Policy fetched; data_collection=true, third_party_sharing=true, retention=false — inadequate disclosure.
  • install_perm_anomaly api small_install_high_perm=true: 300 installs with HIGH-tier permission set.
  • dom_sink_innerhtml crx innerHTML user-controlled sink in main.4964ab1e.js; no CSP present to mitigate DOM-XSS.
  • no_developer_name store developer_name is empty string; verified_publisher=true but no 'Offered by' display name.
  • low_rating store Rating 2.0 on a cursor theme extension; suggests user dissatisfaction.

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • unlimitedStorage low Allows large local storage; minor resource concern.
  • scripting high Combined with *://*/* host access, enables JS injection on every page.
  • host_permissions: *://*/* high Broad access to all sites; dramatically amplifies scripting risk.
  • content_scripts: *://*/* high Content scripts run on every page, expanding attack surface.

Pillar Scores

Permissions7.00
Reputation5.50
Network2.00
Webstore7.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:46
Listing SHA 3198c19eb1a4…
Force block — not fired
Score recovered no
Elapsed