Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN Stream

dmadpoocbhhfaeefeblecpaielloalme
Risk Score
6.14
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 25
Rating 4.9
Last updated 2026-06-22 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ezagirace763@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through stealthpath.space, operated by anonymous gmail developer — total traffic interception risk.
  • Brand impersonation: extension names YouTube and Netflix as supported services but developer is unverified and unrelated to either brand.
  • Privacy policy is Google's own account policy — not scoped to this extension, admits data collection and third-party sharing without disclosure of what THIS extension collects.
  • Free-webmail developer (gmail), no developer name, no verified publisher — zero accountability for a traffic-intercepting proxy.
  • install_url_hijack redirects to stealthpath.space on install; external JS host app.myxavpn.pro and t.me add unexplained third-party surface.

Evidence

  • proxy_permission manifest proxy declared — extension can redirect all Chrome network traffic through arbitrary server controlled by anonymous developer.
  • brand_impersonation store brand_mention.is_impersonation=true; YouTube and Netflix named in description; developer is unverified gmail account.
  • privacy_policy_generic store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — triggers +10.0 Privacy.
  • free_webmail_no_dev_name store developer_email=ezagirace763@gmail.com; developer_name empty; no verified publisher badge.
  • install_url_hijack crx install_url_hijack=true targeting stealthpath.space on install event.
  • external_js_hosts crx js_external_hosts includes app.myxavpn.pro and t.me — not declared in host_permissions, unexplained surface.
  • small_install_high_perm api install_perm_anomaly: 25 installs + proxy (HIGH) — tail-attack-surface concern.
  • geo_diversity api JS hosts span 4 countries (CA, NL, RU, US); RU-hosted infrastructure for a proxy is elevated risk.

Permissions Breakdown

  • proxy high Proxy permission lets extension intercept and redirect ALL browser traffic to arbitrary servers.
  • https://stealthpath.space/* high Host access to the developer's own VPN backend; combined with proxy creates full traffic interception surface.
  • https://cloudflare-dns.com/* medium DNS-over-HTTPS endpoint; reasonable for VPN but enables DNS query observation.
  • https://dns.google/* medium DNS-over-HTTPS endpoint; same rationale as cloudflare-dns.com.

Pillar Scores

Permissions7.00
Reputation8.50
Network5.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:42
Listing SHA 111c291d0487…
Force block — not fired
Score recovered no
Elapsed