Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN-маяк

choldfdafblhjjfdbnibekaakmhnfabc
Risk Score
5.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs
Rating 5.0
Last updated 2026-06-19 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer vale99505@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full browser traffic interception by unverified developer.
  • Install URL hijack opens stealthpath.space on install — unknown third-party domain.
  • Privacy policy is Google's own policy — not scoped to this extension; data handling undisclosed.
  • Free-webmail developer (gmail.com), no developer name, no verified publisher — anonymous operator.
  • No CSP on MV3 extension contacting 3 external hosts including opaque stealthpath.space.

Evidence

  • proxy_permission manifest proxy declared — can redirect all browser traffic through arbitrary servers.
  • install_url_hijack store onInstalled opens https://stealthpath.space/ — unverified third-party domain.
  • generic_privacy_policy store Policy URL is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_dev_no_name store Developer email vale99505@gmail.com; developer_name empty; no verified publisher badge.
  • no_csp manifest csp_present=false on MV3 extension with 3 external host permissions.
  • opaque_vpn_backend manifest stealthpath.space is sole VPN backend; no WHOIS/CT data available; domain unverifiable.
  • geo_diversity api JS hosts span CA, RU, US — includes Russian geo for a VPN extension from anonymous dev.
  • no_install_count store Install count empty — no popularity signal to contextualize risk.

Permissions Breakdown

  • proxy high Allows full network traffic rerouting; highest-risk VPN permission — can intercept all browser traffic.
  • https://stealthpath.space/* high Unknown third-party domain; VPN backend with no verifiable publisher; install-hijack target.
  • https://cloudflare-dns.com/* medium DNS-over-HTTPS access; expected for VPN/proxy but broadens network reach.
  • https://dns.google/* medium DNS-over-HTTPS access; expected for VPN/proxy but broadens network reach.

Pillar Scores

Permissions5.50
Reputation7.50
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:41
Listing SHA 0991d344d537…
Force block — not fired
Score recovered no
Elapsed