Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Авокадо ВПН — ежедневный VPN

cepookalkohkjhbamenfbagblnmfcfmn
Risk Score
4.36
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 10
Rating 5.0
Last updated 2026-07-12 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer kameqoko032@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission enables full MITM on all browser traffic via unvetted vpnfasters.space and app.myxavpn.pro endpoints
  • install_url_hijack opens vpnfasters.space on install — third-party redirect from anonymous dev
  • Privacy policy is Google's own generic policy; does not scope to this extension at all (D clause: +10.0)
  • Free-webmail Gmail dev, no developer name, no verified publisher — anonymous operator
  • Small-install + high-perm anomaly: only 10 users, proxy permission — classic tail-attack surface

Evidence

  • proxy_permission manifest proxy declared — routes all traffic; combined with external hosts app.myxavpn.pro and vpnfasters.space.
  • install_url_hijack store install_url_target=https://vpnfasters.space/ opens on install; third-party domain not controlled by dev.
  • generic_google_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • anonymous_developer store developer_name empty, free Gmail address kameqoko032@gmail.com, no verified publisher badge.
  • free_webmail_no_dev_name store Gmail dev + no name → Reputation floor applies; +1.5 free-webmail, +1.0 no dev name.
  • js_external_hosts crx app.myxavpn.pro (NL), vpnfasters.space, t.me — 3 distinct registrable domains, geo NL+RU.
  • install_perm_anomaly api small_install_high_perm=true: 10 installs with proxy permission — tail-attack surface.
  • no_csp manifest csp_present=false on MV3; v2 fix (b) not triggered on MV3 but noted for network context.

Permissions Breakdown

  • proxy high Routes all browser traffic through attacker-controlled server; full MITM capability.

Pillar Scores

Permissions7.00
Reputation8.00
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:29
Listing SHA 67ee59a00042…
Force block — not fired
Score recovered no
Elapsed