Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN Game Pro

bjfngoeclhbkpgdngfdolcpiofgdlbjm
Risk Score
4.50
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 27
Rating 4.8
Last updated 2026-06-25 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer milumepid39@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission gives full browser traffic interception/redirection to unknown operator behind routekeeper.space
  • Privacy policy is Google's own policy (unscoped); does not disclose what THIS extension collects or shares
  • Free-webmail dev (gmail), no developer name, no verified publisher — anonymous high-capability operator
  • install_url_hijack: onInstalled opens routekeeper.space — monetization/redirect signal
  • Only 27 installs with HIGH-tier permission (proxy) — tail attack surface with high capability-to-reach ratio

Evidence

  • proxy_permission manifest proxy declared — allows full interception and rerouting of all browser HTTP/HTTPS traffic.
  • install_url_hijack crx onInstalled opens https://routekeeper.space/ — 3rd-party redirect on install, monetization pattern.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • anonymous_developer store developer_name empty, gmail dev email milumepid39@gmail.com, no verified publisher, no featured badge.
  • external_hosts_diversity crx JS contacts 5 external hosts across 4 countries (CA, NL, RU, US) incl. app.myxavpn.pro and t.me (Telegram).
  • small_install_high_perm api Only 27 installs with proxy (HIGH) permission — install_perm_anomaly.small_install_high_perm=true.
  • geo_diversity crx JS hosted across 4 countries including RU and NL; country_count>=4 triggers geo-diversity risk.
  • no_csp manifest content_security_policy is null/absent on MV3 extension with external host access.

Permissions Breakdown

  • proxy high Full proxy control redirects all browser traffic; critical capability for a VPN category but still HIGH risk.
  • https://routekeeper.space/* medium Host permission to extension's own backend; matches VPN function but domain is unknown.
  • https://cloudflare-dns.com/* low DNS-over-HTTPS provider; standard for VPN/proxy DNS leak prevention.
  • https://dns.google/* low Google DoH endpoint; standard fallback DNS for VPN proxies.

Pillar Scores

Permissions7.00
Reputation8.50
Network5.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:33
Listing SHA d11ff691f70d…
Force block — not fired
Score recovered no
Elapsed