Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adguard VPN

dijdbcdjngogkbpgldngbflblkbkicla
Risk Score
9.07
Risk Level: Critical
Recommendation: 🚫 BLOCK
Category VPN
Installs 63
Rating 5.0
Last updated 2026-06-10 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer sedatkilli87@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation of AdGuard VPN by a free-webmail Gmail dev with no verified identity; proxy permission redirects all traffic.
  • install_url_hijack confirmed: onInstalled opens neoncloak.space, a suspicious third-party domain also used as a JS external host.
  • Privacy policy is Google's own generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — completely unscoped.
  • JS communicates with app.myxavpn.pro and neoncloak.space — unknown third-party endpoints for a supposed AdGuard product.
  • 58 installs + proxy permission + free-webmail dev + no developer name = classic tail-attack-surface credential-harvesting shell.

Evidence

  • brand_impersonation store Title 'Adguard VPN' with Gmail dev (sedatkilli87@gmail.com), no verified publisher, not affiliated with Adguard Software Ltd.
  • install_url_hijack crx onInstalled opens https://neoncloak.space/ — same domain appears in js_external_hosts; not AdGuard infrastructure.
  • proxy_permission manifest proxy declared; all browser traffic can be intercepted or rerouted by this extension.
  • external_js_hosts crx JS contacts app.myxavpn.pro, neoncloak.space, t.me — no AdGuard domains present.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, third_party_sharing=true — not scoped to this extension.
  • free_webmail_no_dev_name store developer_name empty, developer_email is Gmail; no verifiable business identity behind high-capability VPN extension.
  • small_install_high_perm api 58 installs with HIGH-tier proxy permission flagged by install_perm_anomaly.small_install_high_perm=true.
  • geo_diversity crx JS hosted in NL and RU (2 countries); Russian-hosted endpoint for an AdGuard impersonator is notable.

Permissions Breakdown

  • proxy high Full proxy control over all browser traffic; can redirect, intercept, or suppress any network request.

Pillar Scores

Permissions7.00
Reputation9.00
Network3.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sectestoff8498 6.22 High block 2026-09-10
v3.6 9.07 Critical block 2026-09-02

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:48
Listing SHA a936b27b6082…
Force block — not fired
Score recovered no
Elapsed