Lightiius CRM
ohkakacjaddkccagpciddgcjjbbpcgfl
Risk Score
5.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script on web.whatsapp.com can read all messages/contacts; exfiltrated to multiple wascript.com.br backends.
- Uninstall and install URL hijacks present; install redirects to crm.lightiius.com/freedemo.php.
- Free-webmail dev (gmail) with no verified publisher and no developer name — low accountability.
- Privacy policy not scoped to this extension and third-party sharing undisclosed (third_party_silence=true).
- WhatsApp brand impersonation confirmed by brand_mention; developer is not a confirmed Meta/WhatsApp owner.
Evidence
- uninstall_and_install_url_hijack manifest install_url_hijack=true (target: https://crm.lightiius.com/freedemo.php); uninstall_url_hijack=true.
- whatsapp_brand_impersonation store brand_mention.is_impersonation=true; developer domain is gmail.com, confirmed_owner=false.
- free_webmail_no_dev_name store developer_email=beto18salazar@gmail.com; developer_name empty; no verified publisher.
- privacy_policy_not_scoped api scope_extension=false, data_collection=false, third_party_silence=true — generic unscoped policy.
- multiple_external_backends crx 12 external JS hosts including bit.ly (affiliate/cloaking), 5 wascript.com.br subdomains, whatzi.cloud.
- affiliate_hit_bitly crx threat_intel.affiliate_hits: bit.ly flagged as generic short-link redirector / affiliate cloaking.
- function_constructor_code_finding crx new Function() constructor found in 326-file bundle; no CSP, raising XSS risk.
- no_csp_mv3 manifest content_security_policy=null; csp_present=false on MV3 extension with DOM-sink and Function() findings.
Permissions Breakdown
- unlimitedStorage low Allows large local data; low direct exfil risk.
- storage low Standard key-value storage, low risk.
- alarms low Scheduling only, no data access.
- tabs medium Can read tab URLs and titles across sessions.
- https://web.whatsapp.com/* high Content script on WhatsApp — can read all messages and contact data.
- https://*.whatzi.cloud/* medium Broad access to third-party cloud backend under unknown operator.
- https://*.wascript.com.br/* medium Broad wildcard to external BR domain; multiple subdomains contacted.
Pillar Scores
Permissions2.30
Reputation8.00
Network3.50
Webstore7.50
Maintenance0.00
Privacy9.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:03
Listing SHA
6899f547347e…
Force block
— not fired
Score recovered
no
Elapsed
—