Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Radmin VPN

bmidlejanhnaaopgiljgojghplnaeoaf
Risk Score
6.17
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 11
Rating 5.0
Last updated 2026-06-07 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer kristi.tis@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full interception/rerouting of all browser traffic via unverified infrastructure (cloudmask.space, app.myxavpn.pro)
  • install_url_hijack to cloudmask.space — extension opens third-party URL on install, a monetization/traffic-theft signal
  • Privacy policy is Google's generic account policy, completely unscoped to this extension; data practices unknown
  • Developer is anonymous gmail user with no business identity; VPN-class capability with no accountability
  • JS external hosts span NL and RU; proxy backend is opaque and could redirect or intercept traffic

Evidence

  • install_url_hijack manifest onInstalled opens https://cloudmask.space/ — classic monetization/traffic-hijack shell pattern.
  • proxy_permission manifest proxy declared; routes all browser traffic through extension-controlled servers with no verified backend.
  • js_external_hosts crx Extension contacts app.myxavpn.pro, cloudmask.space, t.me — none match 'Radmin VPN' branding.
  • privacy_policy_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — D rule applies (+10).
  • developer_identity store Developer is kristi.tis@gmail.com with no name, no business domain, free webmail only.
  • small_install_high_perm api Only 11 installs with HIGH-tier proxy permission — tail attack surface anomaly flagged.
  • host_geo_diversity crx JS hosts span NL and RU (2 countries); RU-hosted proxy backend raises interception risk.
  • brand_impersonation_risk store Title claims 'Radmin VPN' (established Famatech product) but developer has no connection to Famatech.

Permissions Breakdown

  • proxy high Full proxy control routes all browser traffic; very high abuse potential for MitM or censorship bypass.

Pillar Scores

Permissions8.00
Reputation8.50
Network4.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:43
Listing SHA e798d29f2487…
Force block — not fired
Score recovered no
Elapsed