Chrome Web Store
11Versions
2Code reviewed

Caution required

Suspicious in code review

Our reviewer found behaviour consistent with malware, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Hockey Shootout is rated caution by Extension Auditor. Our code review reported 3 findings (1 high, 2 medium), led by privilege escalation. It comes from a publisher with 28 extensions and was last updated in April 2026.

Key findings

  • high· privilege escalation —externally_connectable is opened to <all_urls>, meaning any web page on the internet may call chrome.runtime.sendMessage into this extension, yet no file in the complete 311-file package registers chrome.runtime.onMessageExternal or onConnectExternal (verified by grep across,,, and every other script). A hockey mini-game that never accepts external messages has no reason to declare the broadest possible caller surface. Paired with the host permission, which is likewise referenced nowhere in the codebase, this is unused privileged capability staged in the manifest that a future silent update could activate without any new permission prompt.
  • medium· phishing —The JSON fields protxt and rating returned by are assigned straight to innerHTML inside the privileged chrome-extension:// origin, with no sanitisation and no schema constraint. The server therefore fully controls arbitrary markup rendered on the extension's own page, which can be swapped at any time into a credential-harvesting form, a fake browser or Google prompt, or an off-site link that inherits the trust users place in an installed extension. The extension_pages CSP (script-src 'self') blocks inline script execution, so this is not remote code execution, but it is an operator-controlled UI surface that is served from a domain the IoC feed lists as a shared C2.
  • medium· other —The game page embeds a hidden, high z-index banner whose image and click destination both point at multiaccount.cloudapi.stream, an operator-controlled host on the same domain the IoC feed flags as the campaign C2. Because both the artwork and the link target are fetched remotely, the publisher can repoint this slot at any landing page after installation without shipping an extension update, and the remote image fetch also leaks a per-session beacon. Nothing in ever reveals this element, so it is dormant content the operator can enable server-side.

The game itself is clean, unmodified Arcade code: (518 KB) is TweenJS plus the stock Hockey Shootout engine with zero network calls and zero chrome.* API use, is stock, and is a plain string table, so the ML regex hits (js_innerhtml 37, js_appendchild 51, 1.97 MB of JS) are game-engine code and vendored libraries, not malice. What contradicts a clean verdict is the thin wrapper the publisher added around it::17 declares externally_connectable for <all_urls> while no file in the full 311-file package registers onMessageExternal or onConnectExternal,:30 requests which is never referenced anywhere, and:43-47 renders server-controlled HTML from mines.cloudapi.stream directly into the extension origin. The IoC note tying cloudapi.stream to the Socket 108-extension shared-C2 campaign and the publisher's malicious rate corroborate the ML score as context, but I found no code path in this version giving that C2 access to cookies, identity, browsing history or page content (there are no content scripts and permissions is empty), so I stop at suspicious rather than likely_malicious.

Hockey Shootout

Hockey Shootout Chrome extension security report

ID: cehdkmmfadpplgchnbjgdngdcjmhlfcc

Supported Languages

🇸🇦Arabic
🇧🇬Bulgarian
🇨🇳Chinese (Simplified)
🇹🇼Chinese (Traditional)
🇭🇷Croatian
🇨🇿Czech
🇩🇰Danish
🇳🇱Dutch
🇺🇸English
🇪🇪Estonian
🇵🇭Filipino
🇫🇮Finnish
🇫🇷French
🇩🇪German
🇬🇷Greek
🇮🇱Hebrew
🇭🇺Hungarian
🇮🇩Indonesian
🇮🇹Italian
🇯🇵Japanese
🇰🇷Korean
🇱🇻Latvian
🇱🇹Lithuanian
🇳🇴Norwegian
🇮🇷Persian
🇵🇱Polish
🇷🇴Romanian
🇷🇺Russian
🇷🇸Serbian
🇸🇰Slovak
🇸🇮Slovenian
🇪🇸Spanish
🇸🇪Swedish
🇹🇭Thai
🇹🇷Turkish
🇺🇦Ukrainian
🇻🇳Vietnamese

Extension Info & Metadata

Status
Active
Version
2.6.2
Size
12.19 MB
Rating
5.0/5
Reviews
2
Users
985
Type
Extension
Updated
Apr 16, 2026
Category
Games
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
28extensions
10 no longer listed

Publisher Contextual Analysis

Author
YanaProject
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
28
Active
18
Obsolete
10
Listed
28
Unlisted
0
Users
5,113

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact
https://www.googleapis.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://wheel.cloudapi.stream/*
Host
Medium
Host permission — access limited to this URL pattern.
https://mines.cloudapi.stream/*
Host
Medium
Host permission — access limited to this URL pattern.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: https://www.googleapis.com/*
  • 1 high
  • 2 medium

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Hockey Shootout: Chrome extension game

Read the publisher’s full description

Hockey Shootout is the perfect pastime for all hockey fans and arcade game enthusiasts. Test your goal-scoring skills, improve your techniques, and reach new heights in this captivating mini-game for your Chrome browser.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
35

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
2.6.2
Latest
12.19 MBCaution0N/A
2.6.1
12.19 MBCaution0N/A
2.5.4
12.19 MBCaution—N/A
1.3.3
8.55 MBCaution—N/A
1.3.2
8.55 MBCaution—N/A
1.3.1
8.55 MBCaution—N/A
1.3.0
8.55 MBCaution—N/A
1.1.0
8.54 MBCaution—N/A
1.0.0
9.48 MBCaution—N/A
1.3.4
8.55 MBCaution—N/A
Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.