Lamine Yamal Wallpaper
nnblldaiefjihkbigjppimaigmkfdonm
Risk Score
3.92
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack to owhit.com — classic monetization shell pattern collecting departure telemetry.
- Install URL hijack to owhit.com — tracks installs via 3rd-party domain on every fresh install.
- Privacy policy is Google's own account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- NewTab override with free-webmail dev, no developer name, no verified publisher — high fraud surface.
- 8 external JS hosts (YouTube, Instagram, Netflix, X, ChatGPT) with no CSP; broad undisclosed network reach.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://owhit.com/uninstall; 3rd-party monetization shell fingerprint.
- install_url_hijack crx onInstalled opens https://owhit.com/lamine-yamal-wallpaper; classic traffic monetization redirect.
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab captured by extension.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_devname store Dev email servetyahya06@gmail.com, developer_name empty, no verified publisher badge.
- js_external_hosts crx 8 external hosts: owhit.com, chatgpt.com, youtube.com, instagram.com, netflix.com, x.com, google.com, chrome.google.com.
- no_csp manifest content_security_policy null; MV3 default CSP applies but no explicit restriction on connect-src.
- low_installs_newtab store 738 installs; fan-content wallpaper shell with newtab override and 3rd-party URL hijacks.
Permissions Breakdown
- search medium Allows interaction with browser search; paired with newtab override amplifies search monetization risk.
- chrome_url_overrides.newtab high Replaces every new tab with extension page; primary vector for ad/affiliate monetization and tracking.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 14:24
Listing SHA
4e2152e9aa27…
Force block
— not fired
Score recovered
no
Elapsed
—