Хэппи VPN
aojolglblgegdlejhldpeadnglkcheba
Risk Score
5.36
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows full traffic interception and rerouting through cloudmask.space (RU/NL hosted)
- Install URL hijack opens cloudmask.space on install; extension contacts app.getmyxa.com and t.me at runtime
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing
- Free-webmail developer (gmail), no developer name, no verified publisher — zero accountability
- MV3 with no CSP; 3 external JS hosts across NL and RU jurisdictions for a proxy extension
Evidence
- proxy_permission manifest proxy declared; routes all browser traffic; paired with external host cloudmask.space (RU/NL).
- install_url_hijack store onInstalled opens https://cloudmask.space/ — third-party site unrelated to chrome store listing.
- js_external_hosts crx app.getmyxa.com, cloudmask.space, t.me — 3 distinct external domains including Telegram.
- generic_privacy_policy store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity store Free Gmail address egositburak@gmail.com, no developer name, no verified publisher badge.
- geo_diversity api JS hosts span NL and RU (country_count=2); RU jurisdiction increases traffic-intercept risk for proxy.
- no_csp manifest content_security_policy is null; MV3 default mitigates eval but no explicit script-src restriction.
- cve_findings crx No CVEs detected; no JS libraries bundled.
Permissions Breakdown
- proxy high Can reroute all browser traffic through attacker-controlled servers; critical capability for a VPN shell.
Pillar Scores
Permissions6.50
Reputation7.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:01
Listing SHA
a3f2c9797e1b…
Force block
— not fired
Score recovered
no
Elapsed
—