Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TOP ВПН

bifgpflmljboegdapmikafhpilijdead
Risk Score
4.43
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 4
Rating 5.0
Last updated 2026-06-18 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer asdro1905@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows complete traffic rerouting through unknown servers (app.myxavpn.pro, silashield.space).
  • Privacy policy is Google's own policy — not scoped to this extension; developer admitted data collection + 3rd-party sharing.
  • Free-webmail developer (asdro1905@gmail.com), no name, no business domain — unverifiable identity.
  • install_url_hijack: extension opens a 3rd-party URL on install (unknown target).
  • Geo-diversity: JS hosts span CA/NL/RU/US; silashield.space is an opaque domain with no known reputation.

Evidence

  • proxy_permission manifest proxy declared — full browser traffic interception capability for a 4-install, unverified VPN.
  • install_url_hijack crx install_url_hijack=true; extension redirects user on install to unknown 3rd-party URL.
  • external_hosts crx Contacts app.myxavpn.pro, silashield.space, t.me — opaque/unknown domains outside declared host_permissions.
  • privacy_policy_generic store Policy URL is Google Account privacy page, scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store No developer name, free Gmail address asdro1905@gmail.com, no verified publisher status.
  • geo_diversity crx JS hosts in 4 countries including RU; host silashield.space unrecognized; country_count=4 triggers +1.5.
  • small_install_high_perm api install_perm_anomaly: 4 installs with HIGH-tier proxy permission — tail attack surface.
  • no_csp manifest csp_present=false on MV3; MV3 has default strict CSP so no additional penalty, but noted.

Permissions Breakdown

  • proxy high Full proxy control; can reroute all browser traffic through attacker-controlled servers.
  • https://cloudflare-dns.com/* medium DoH endpoint access; legitimate for VPN DNS but grants outbound DNS query capability.
  • https://dns.google/* medium DoH endpoint access; same pattern as above.

Pillar Scores

Permissions7.50
Reputation8.00
Network5.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:35
Listing SHA 5b75b2a9717d…
Force block — not fired
Score recovered no
Elapsed