Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lug VPN — Зелёный щит приватности

ekpicjaibbcffjfenpffjkifhiehcbfm
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 117
Rating 4.9
Last updated 2026-04-16 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer milumepid39@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through korovkavpn.space — an unknown RU-hosted server with no verified operator identity.
  • Developer is anonymous (no name, free Gmail, no business domain); no accountability if proxy server exfiltrates data.
  • Privacy policy is Google's own account policy — not scoped to this extension at all; admits data collection & 3rd-party sharing.
  • External JS host korovkavpn.space is RU-geolocated; no threat-intel clearance and no WAF/CDN transparency.
  • tiny install base (117) + high-impact permission = tail-attack-surface; easy to fly under radar.

Evidence

  • proxy_permission manifest proxy declared; routes all Chrome traffic through developer-controlled server korovkavpn.space (RU).
  • anonymous_developer store Developer name empty; email milumepid39@gmail.com (free webmail, numbered alias pattern).
  • generic_privacy_policy store Privacy URL is Google account policy (479 KB); scope_extension=false, data_collection=true, third_party_sharing=true.
  • external_js_host crx js_external_hosts: [korovkavpn.space] — single RU domain, no bad-host hit but unverified.
  • install_perm_anomaly api 117 installs + high-tier proxy permission flagged as small_install_high_perm=true.
  • host_geo_diversity api All external JS served from RU only; single-country RU footprint for a VPN product is notable.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals.
  • cve_findings crx cve_findings_raw empty; no known CVEs detected in bundled libraries.

Permissions Breakdown

  • proxy high Allows rerouting all browser traffic through attacker-controlled servers; highest-impact single permission for VPN.

Pillar Scores

Permissions2.00
Reputation8.00
Network2.00
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:53
Listing SHA 0ff370aae63c…
Force block — not fired
Score recovered no
Elapsed