Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Белый VPN – чистый proxy с лёгким интерфейсом

adbicacljgblmefpmcffdjmcbagbejji
Risk Score
5.35
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 12
Rating
Last updated 2026-05-18 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer vale99505@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception/redirection through developer-controlled server sverchvpn.space
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing
  • Developer uses free Gmail with no name; free-webmail + no dev name pattern raises accountability concern
  • install_url_hijack=true: extension opens a 3rd-party URL on install, classic monetization/tracking signal
  • External JS host sverchvpn.space (RU-hosted) embedded in VPN extension with no CSP — traffic and code trust both delegated to unknown party

Evidence

  • proxy_permission manifest proxy declared — can intercept and reroute all browser TCP connections through sverchvpn.space.
  • install_url_hijack store install_url_hijack=true; extension opens external URL on install — monetization/tracking signal.
  • js_external_host crx External host sverchvpn.space referenced in JS; RU-hosted, unknown registrant, no CSP to constrain it.
  • privacy_policy_generic store PP is Google account policy (479KB); scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) → +10.
  • free_webmail_no_devname store Developer email vale99505@gmail.com, developer_name empty; no business identity verifiable.
  • small_install_high_perm api Only 12 installs with HIGH-tier proxy permission; install_perm_anomaly.small_install_high_perm=true.
  • no_csp manifest csp_present=false on MV3; no content_security_policy defined despite external JS host.
  • unverified_publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals present.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled server; highest-impact single permission.

Pillar Scores

Permissions5.00
Reputation8.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:31
Listing SHA e0a341d87458…
Force block — not fired
Score recovered no
Elapsed