VPN Stream
dmadpoocbhhfaeefeblecpaielloalme
Risk Score
6.14
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes ALL browser traffic through stealthpath.space, operated by anonymous gmail developer — total traffic interception risk.
- Brand impersonation: extension names YouTube and Netflix as supported services but developer is unverified and unrelated to either brand.
- Privacy policy is Google's own account policy — not scoped to this extension, admits data collection and third-party sharing without disclosure of what THIS extension collects.
- Free-webmail developer (gmail), no developer name, no verified publisher — zero accountability for a traffic-intercepting proxy.
- install_url_hijack redirects to stealthpath.space on install; external JS host app.myxavpn.pro and t.me add unexplained third-party surface.
Evidence
- proxy_permission manifest proxy declared — extension can redirect all Chrome network traffic through arbitrary server controlled by anonymous developer.
- brand_impersonation store brand_mention.is_impersonation=true; YouTube and Netflix named in description; developer is unverified gmail account.
- privacy_policy_generic store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — triggers +10.0 Privacy.
- free_webmail_no_dev_name store developer_email=ezagirace763@gmail.com; developer_name empty; no verified publisher badge.
- install_url_hijack crx install_url_hijack=true targeting stealthpath.space on install event.
- external_js_hosts crx js_external_hosts includes app.myxavpn.pro and t.me — not declared in host_permissions, unexplained surface.
- small_install_high_perm api install_perm_anomaly: 25 installs + proxy (HIGH) — tail-attack-surface concern.
- geo_diversity api JS hosts span 4 countries (CA, NL, RU, US); RU-hosted infrastructure for a proxy is elevated risk.
Permissions Breakdown
- proxy high Proxy permission lets extension intercept and redirect ALL browser traffic to arbitrary servers.
- https://stealthpath.space/* high Host access to the developer's own VPN backend; combined with proxy creates full traffic interception surface.
- https://cloudflare-dns.com/* medium DNS-over-HTTPS endpoint; reasonable for VPN but enables DNS query observation.
- https://dns.google/* medium DNS-over-HTTPS endpoint; same rationale as cloudflare-dns.com.
Pillar Scores
Permissions7.00
Reputation8.50
Network5.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:42
Listing SHA
111c291d0487…
Force block
— not fired
Score recovered
no
Elapsed
—