VPN для браузера
cmplhaampagiakkffmgjndcjdgbglbln
Risk Score
6.24
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission allows all browser traffic to be silently rerouted through attacker-controlled netroutehub.space
- Google privacy policy used — does not scope to this extension, admits data collection and third-party sharing
- Install URL hijack: onInstalled opens netroutehub.space, a third-party domain
- Free-webmail dev (gmail), no developer name, no business website — zero accountability
- JS contacts app.myxavpn.pro and netroutehub.space (NL+RU geo), no CSP on MV3 extension with only 37 installs
Evidence
- proxy_permission manifest proxy declared — can redirect all browser HTTP/S traffic to any server the extension chooses.
- install_url_hijack crx onInstalled opens https://netroutehub.space — third-party domain, monetization/tracking unknown.
- js_external_hosts crx Extension contacts app.myxavpn.pro, netroutehub.space, t.me — 3 distinct external domains (NL, RU).
- privacy_policy_generic store Policy URL is Google's own account policy — scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_devname store Developer email binoyihe32@gmail.com, developer_name empty — no verifiable business identity.
- no_csp manifest csp_present=false on MV3; +2.0 network penalty not applicable (MV3), but no explicit policy is still a gap.
- small_install_high_perm api 37 installs with HIGH-tier proxy permission — tail-attack-surface anomaly flagged.
- cve_findings crx No CVEs detected in bundled JS libraries.
Permissions Breakdown
- proxy high Full proxy control; can route all browser traffic through attacker-controlled servers.
Pillar Scores
Permissions7.00
Reputation8.50
Network4.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:31
Listing SHA
31c665177487…
Force block
— not fired
Score recovered
no
Elapsed
—