Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spy x Family Cursor - Custom Anime Cursor for Chrome

oiogpbnonmepejhhmhgnmmpofkknomcf
Risk Score
6.06
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 307
Rating
Last updated 2026-03-10 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer heroking15@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to tabplugins.com — traffic-monetization shell; high confidence malicious pattern.
  • Install URL hijack to tabplugins.com on every install — redirects user to 3rd-party on installation.
  • Privacy policy is Google's own generic account policy — admits 3rd-party sharing with no extension scope.
  • scripting + *://*/* = full page-content injection on all sites visited by the user.
  • Free-webmail dev, no verified publisher, 307 installs with HIGH permissions — tail attack surface.

Evidence

  • uninstall_url_hijack manifest setUninstallURL → tabplugins.com/cursors/ — 3rd-party monetization shell signal (+3.0 Webstore).
  • install_url_hijack manifest onInstalled opens tabplugins.com/spy-x-family-cursor/ — 3rd-party redirect on install (+2.0 Webstore).
  • privacy_policy_google_generic store Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
  • broad_host_with_scripting manifest scripting + *://*/* host_permissions: can inject arbitrary JS into every page the user visits.
  • free_webmail_developer store heroking15@gmail.com — free webmail, no verified business; Reputation floor >= 7.5.
  • dom_sink_innerhtml crx innerHTML sink in main.4964ab1e.js; no CSP present — DOM-XSS risk elevated (+2.0 Code Quality via FIX B).
  • small_install_high_perm api 307 installs with HIGH-tier permissions (scripting + *://*/*) — tail attack surface anomaly (+1.5 Webstore).
  • js_external_hosts crx Extension references tabplugins.com, reactjs.org, chrome.google.com externally (>3 domains: +1.5 Network).

Permissions Breakdown

  • storage low Stores cursor preferences locally; low risk in isolation.
  • unlimitedStorage low Allows unlimited local storage; minor escalation of storage risk.
  • scripting high Combined with *://*/* host access, allows arbitrary script injection into every page.
  • *://*/* high Broad host permission enables script injection and data access on all sites.

Pillar Scores

Permissions6.50
Reputation7.50
Network4.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:50
Listing SHA 3520766d202b…
Force block — not fired
Score recovered no
Elapsed