Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Оса Стелс — Кибер-щит для браузера

aemjnabgfabjlcojhbablmedhbnmpcgj
Risk Score
6.05
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 7
Rating 5.0
Last updated 2026-04-12 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer norkienej@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows complete traffic interception and redirection for all browser activity
  • Free webmail dev (gmail), no developer name, no verified publisher — anonymous operator
  • Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing
  • External JS hosted on osavpn.su (RU-hosted unknown domain) — potential for remote code injection
  • Only 7 installs with a high-tier permission (proxy) — tail attack surface, very low accountability

Evidence

  • proxy permission declared manifest proxy is HIGH-risk; can route all browser traffic through any server the extension designates.
  • external JS host: osavpn.su crx JS loaded from osavpn.su (Russia). Unknown domain; no threat-intel hit but unverifiable supply chain.
  • developer identity — free webmail, no name store norkienej@gmail.com, no developer_name set, not verified publisher, not featured.
  • privacy policy is generic Google policy store myaccount.google.com/privacypolicy: scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_perm_anomaly: small_install_high_perm api Only 7 installs with proxy (HIGH-tier). Tail-attack-surface risk.
  • no CSP defined manifest csp_present=false; MV3 provides some default protection but extension lacks explicit CSP.
  • host geo: Russia only crx All JS external hosts geolocate to RU; combined with proxy permission raises interception risk.
  • no code findings / obfuscation crx code_findings_raw empty, obfuscation_score=0.0; static scan clean but external host limits confidence.

Permissions Breakdown

  • proxy high Full proxy control can redirect all browser traffic to attacker-controlled servers.

Pillar Scores

Permissions8.00
Reputation8.50
Network4.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:28
Listing SHA 66df3b1e970f…
Force block — not fired
Score recovered no
Elapsed