Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN Simple

elflhijmcekbfdjkabgphiepeclgmjgl
Risk Score
4.50
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 10
Rating
Last updated 2026-06-22 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer silviaferr79@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through stealthpath.space — unknown, unvetted operator with only 10 installs.
  • Install-URL hijack opens stealthpath.space on install; classic phone-home / affiliate redirect pattern.
  • Privacy policy is Google's own policy — completely unscoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail developer (silviaferr79@gmail.com), no developer name, no verified publisher — zero accountability.
  • JS contacts app.myxavpn.pro and t.me in addition to proxy infrastructure — undisclosed external endpoints.

Evidence

  • proxy_permission manifest proxy declared — can redirect all browser HTTP/HTTPS traffic to stealthpath.space or any host.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens https://stealthpath.space/ — undisclosed third-party redirect.
  • generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_dev_name store Developer is silviaferr79@gmail.com with empty developer_name; no business identity verifiable.
  • undisclosed_external_hosts crx JS contacts app.myxavpn.pro and t.me — neither declared in host_permissions nor explained in description.
  • geo_diversity api JS hosts span CA, NL, RU, US (4 countries); country_count>=4 for non-VPN-core hosts raises routing concern.
  • install_perm_anomaly api small_install_high_perm=true: only 10 installs with proxy (HIGH-tier) permission — tail attack surface.
  • no_csp manifest csp_present=false on MV3; no content_security_policy declared — v2 calibration +2.0 network applied.

Permissions Breakdown

  • proxy high Routes all browser traffic through attacker-controlled proxy; highest-impact VPN-class permission.
  • https://stealthpath.space/* high Unknown third-party domain receives proxy config and is the install-redirect target.
  • https://cloudflare-dns.com/* low Public DNS-over-HTTPS endpoint; expected for VPN DNS resolution.
  • https://dns.google/* low Public DNS-over-HTTPS endpoint; expected for VPN DNS resolution.

Pillar Scores

Permissions7.00
Reputation8.50
Network5.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:26
Listing SHA 8405c29f77ef…
Force block — not fired
Score recovered no
Elapsed