Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TOP ВПН-Крепкое соединение

bchelkjkilnlomoehihopndkjjhlcgla
Risk Score
5.55
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs
Rating
Last updated 2026-06-27 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer aslikap21@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows complete rerouting of all browser traffic through unverified VPN infrastructure including silashield.space (RU-hosted).
  • Privacy policy points to Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
  • Developer uses free Gmail address with no name, no verified publisher status, and no business domain.
  • install_url_hijack=true: extension opens external URL on install — likely to app.myxavpn.pro or silashield.space.
  • JS external hosts include silashield.space (NL/RU) and t.me (Telegram), raising anonymity/exfil concerns for a VPN extension.

Evidence

  • proxy_permission manifest proxy declared — full traffic interception capability; no verified publisher to establish trust.
  • install_url_hijack crx install_url_hijack=true; extension opens 3rd-party URL on install (target not captured but external hosts include silashield.space, t.me).
  • external_hosts crx JS contacts: app.myxavpn.pro, silashield.space, t.me, cloudflare-dns.com, dns.google — 4 countries CA/NL/RU/US.
  • privacy_policy_google_generic store Policy URL is Google's own account policy (479 KB), not extension-scoped; data_collection=true, third_party_sharing=true.
  • developer_identity store No developer name, free Gmail (aslikap21@gmail.com), no verified publisher, no business domain.
  • geo_diversity api JS hosts span 4 countries (CA, NL, RU, US); RU-hosted endpoint silashield.space is notable for a VPN product.
  • no_csp manifest csp_present=false on MV3; no content_security_policy declared, reducing script injection defenses.
  • install_count_missing store Install count not available; rating=0 — very new or unlisted extension with no community validation.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; maximum network interception risk.
  • https://cloudflare-dns.com/* medium DNS-over-HTTPS host access; needed for VPN DNS resolution but broadens network reach.
  • https://dns.google/* medium DNS-over-HTTPS host access; same rationale as cloudflare-dns.

Pillar Scores

Permissions7.50
Reputation7.50
Network5.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:41
Listing SHA ee07a2db4ebb…
Force block — not fired
Score recovered no
Elapsed