VPN-маяк
choldfdafblhjjfdbnibekaakmhnfabc
Risk Score
5.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows full browser traffic interception by unverified developer.
- Install URL hijack opens stealthpath.space on install — unknown third-party domain.
- Privacy policy is Google's own policy — not scoped to this extension; data handling undisclosed.
- Free-webmail developer (gmail.com), no developer name, no verified publisher — anonymous operator.
- No CSP on MV3 extension contacting 3 external hosts including opaque stealthpath.space.
Evidence
- proxy_permission manifest proxy declared — can redirect all browser traffic through arbitrary servers.
- install_url_hijack store onInstalled opens https://stealthpath.space/ — unverified third-party domain.
- generic_privacy_policy store Policy URL is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev_no_name store Developer email vale99505@gmail.com; developer_name empty; no verified publisher badge.
- no_csp manifest csp_present=false on MV3 extension with 3 external host permissions.
- opaque_vpn_backend manifest stealthpath.space is sole VPN backend; no WHOIS/CT data available; domain unverifiable.
- geo_diversity api JS hosts span CA, RU, US — includes Russian geo for a VPN extension from anonymous dev.
- no_install_count store Install count empty — no popularity signal to contextualize risk.
Permissions Breakdown
- proxy high Allows full network traffic rerouting; highest-risk VPN permission — can intercept all browser traffic.
- https://stealthpath.space/* high Unknown third-party domain; VPN backend with no verifiable publisher; install-hijack target.
- https://cloudflare-dns.com/* medium DNS-over-HTTPS access; expected for VPN/proxy but broadens network reach.
- https://dns.google/* medium DNS-over-HTTPS access; expected for VPN/proxy but broadens network reach.
Pillar Scores
Permissions5.50
Reputation7.50
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:41
Listing SHA
0991d344d537…
Force block
— not fired
Score recovered
no
Elapsed
—