KATSEYE Wallpaper
pagodnomjfjjbokibkbfieffdhafjfji
Risk Score
5.69
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack to owhit.com — classic monetization shell pattern tracking departing users.
- Install URL hijack to owhit.com — opens 3rd-party page on install, typical ad-redirect behavior.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- Developer is a free-webmail Gmail address with no developer name or verified business identity.
- NewTab override + search permission enables full replacement of browsing start surface with potential ad monetization.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://owhit.com/uninstall; 3rd-party tracking on uninstall.
- install_url_hijack crx onInstalled opens https://owhit.com/katseye-wallpaper; ad-monetization redirect on install.
- newtab_override manifest chrome_url_overrides.newtab = index.html; replaces every new tab with extension content.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
- privacy_policy_classification api scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) → +10.0 privacy.
- developer_identity store Dev email canb08898@gmail.com (numbered alias), no developer name, free webmail only.
- verified_publisher store verified_publisher=true; applied -2.0 reputation discount but floor raised by free-webmail + numbered alias.
- external_hosts crx JS contacts chatgpt.com, instagram.com, youtube.com, x.com, owhit.com — wide reach for a wallpaper NewTab.
Permissions Breakdown
- search medium Allows overriding search provider; medium risk on its own but combined with newtab override is elevated.
- chrome_url_overrides.newtab medium Replaces the browser new tab page; primary surface for monetization/redirect abuse.
Pillar Scores
Permissions5.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 06:26
Listing SHA
20a36ae7fb6a…
Force block
— not fired
Score recovered
no
Elapsed
—