Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN Hidden

ejpngffggkahecooncogchbchpngfokj
Risk Score
4.46
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 158
Rating 4.8
Last updated 2026-06-25 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer milumepid39@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission grants full traffic redirection capability to unverified gmail developer with no business identity.
  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
  • install_url_hijack redirects to routekeeper.space on install; extension contacts app.myxavpn.pro and t.me externally.
  • Developer is free-webmail with no name, no verified publisher status, and no business domain.
  • geo-diverse JS hosts (CA, NL, RU, US) including Russian-geolocated endpoint for a low-install VPN extension.

Evidence

  • proxy_permission manifest proxy declared — can reroute all browser traffic; HIGH risk for unverified VPN.
  • install_url_hijack crx install_url_hijack=true; target=https://routekeeper.space/ on extension install.
  • free_webmail_no_dev_name store developer_email=milumepid39@gmail.com; developer_name empty; no business website.
  • generic_google_privacy_policy api Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • external_hosts_include_myxavpn_and_telegram crx js_external_hosts includes app.myxavpn.pro and t.me — not listed in manifest host_permissions.
  • geo_diversity_russia api JS hosts span CA, NL, RU, US (4 countries); RU-geolocated endpoint flagged for VPN with 158 installs.
  • small_install_high_perm_anomaly api install_perm_anomaly: small_install_high_perm=true; 158 installs with proxy permission.
  • no_csp manifest content_security_policy=null; csp_present=false on MV3 extension.

Permissions Breakdown

  • proxy high Full proxy control can redirect all browser traffic through attacker-chosen servers.
  • https://routekeeper.space/* high Unknown third-party domain; used as install hijack target and proxy backend.
  • https://cloudflare-dns.com/* low Legitimate public DNS-over-HTTPS endpoint; plausible for VPN DNS resolution.
  • https://dns.google/* low Legitimate Google DNS-over-HTTPS; plausible for VPN DNS resolution.

Pillar Scores

Permissions8.00
Reputation7.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:36
Listing SHA 050dcff8b073…
Force block — not fired
Score recovered no
Elapsed