Дядя Ваня VPN
emankpkmfimhfhilhgfmmhgahcmhihbh
Risk Score
4.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Proxy permission lets extension silently route all browser traffic through usachvpn.su (RU-hosted), enabling MitM.
- Developer is anonymous (no name, free-webmail Gmail, no business site) — no accountability.
- Privacy policy is Google's own policy, completely unscoped to this extension; admits data collection and third-party sharing.
- Install URL hijack on first install opens unknown third-party URL.
- Tiny install base (49) with high-impact permission is a tail-attack-surface concern.
Evidence
- proxy_permission manifest proxy declared — can redirect all browser traffic to usachvpn.su (RU).
- install_url_hijack crx install_url_hijack=true; target unknown — opens 3rd-party page on install.
- external_host crx js_external_hosts: usachvpn.su — sole RU-domain proxy backend, no transparency.
- reputation_anonymous_dev store No developer name, free-webmail Gmail (imawocigi29@gmail.com), no verified publisher.
- privacy_policy_generic store Policy is Google Account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
- small_install_high_perm api 49 installs + proxy HIGH permission flagged by install_perm_anomaly.
- csp_absent manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
- free_webmail_no_name store Developer email is numbered-alias-style Gmail with empty developer_name — floor reputation.
Permissions Breakdown
- proxy high Full proxy control can redirect all browser traffic through attacker-controlled servers.
Pillar Scores
Permissions2.00
Reputation8.50
Network2.00
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:10
Listing SHA
78e5c9559f71…
Force block
— not fired
Score recovered
no
Elapsed
—