Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Амнезия VPN — лёгкое proxy-подключение для браузера

emkbmmhneldhbgpkaomgjjohdcfeapbj
Risk Score
5.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 170
Rating 5.0
Last updated 2026-05-24 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer binoyihe32@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through developer-controlled servers with no accountability
  • Privacy policy is Google's own policy — not scoped to this extension at all; admits data collection and 3rd-party sharing
  • Developer is anonymous (no name, free Gmail, no verified publisher), making future malicious update undetectable
  • install_url_hijack: onInstalled opens an external URL (app.getmyxa.com / t.me) — classic monetization/redirect pattern
  • Only 170 installs + HIGH proxy permission = ideal tail-attack-surface; low scrutiny, high capability

Evidence

  • proxy_permission manifest proxy declared — can silently redirect all browser traffic to any server the developer controls.
  • anonymous_developer store No developer name, Gmail contact only (binoyihe32@gmail.com), no verified publisher, no featured badge.
  • generic_privacy_policy store Privacy policy points to Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_url_hijack crx install_url_hijack=true — onInstalled opens external URL (app.getmyxa.com or t.me).
  • external_js_hosts crx JS contacts app.getmyxa.com (RU) and t.me; 2 distinct external registrable domains, geo diversity NL+RU.
  • tail_attack_surface api install_perm_anomaly: small_install_high_perm=true (170 installs + proxy). Low scrutiny, high capability.
  • no_csp manifest csp_present=false on MV3; +2.0 Network per v2 calibration (MV2+no-CSP rule not applicable but noted absent).
  • free_webmail_dev store Gmail developer with no business website or domain; Reputation floor triggered at 7.5+ per rubric.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers; full network interception capability.

Pillar Scores

Permissions6.50
Reputation8.00
Network4.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:28
Listing SHA 5876ba79b8ed…
Force block — not fired
Score recovered no
Elapsed