Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Drone Shield — ретро-защита сети

afpiijfkjbkkfoeepflocpfcmghcohfi
Risk Score
5.79
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 3
Rating 5.0
Last updated 2026-04-10 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer ekugabezu505@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through zhukvpn.online (RU-hosted), enabling full MITM interception
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing
  • Developer is anonymous free-webmail (gmail), no dev name, no verified publisher status
  • Sole external JS host zhukvpn.online is Russia-geolocated; domain identity unverifiable
  • 3 installs with HIGH-tier proxy permission is a tail-attack-surface red flag

Evidence

  • proxy_permission manifest proxy declared — can route all browser traffic to zhukvpn.online without user per-request consent.
  • external_js_host_ru crx js_external_hosts: [zhukvpn.online]; host_geo_diversity countries: [RU] — sole infrastructure in Russia.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
  • privacy_admits_collection_sharing api policy classification: scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) → +10.0.
  • anonymous_developer store developer_name empty, free-webmail email ekugabezu505@gmail.com, no verified publisher badge.
  • install_perm_anomaly api installs=3 with high-tier permission (proxy); small_install_high_perm=true.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; static analysis surface clean but proxy capability is self-sufficient.

Permissions Breakdown

  • proxy high Redirects all browser traffic through arbitrary SOCKS5 server; full network interception capability.

Pillar Scores

Permissions7.00
Reputation8.00
Network4.50
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:55
Listing SHA 4abc8307e742…
Force block — not fired
Score recovered no
Elapsed