Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

StreamTube Proxy

epkcfhiniijndongcpclcfogmbpphfga
Risk Score
5.68
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 100,000
Rating 4.2
Last updated 2026-08-12
Manifest version MV3
CSP present ❌ no
Developer tiktokextensions@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception/redirection for all browser traffic despite narrow stated scope.
  • Developer is a free-webmail Gmail account named 'tiktokextensions' with no verified business identity.
  • Privacy policy is Google's own generic policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
  • Install URL hijack redirects new installs to a Notion page under an unrelated domain (swaponline.notion.site).
  • Extension fetches from raw.githubusercontent.com at runtime — potential for remote code/config injection.

Evidence

  • proxy_permission manifest proxy declared; routes all browser traffic — no host-scoping in proxy API regardless of host_permissions.
  • free_webmail_dev store Developer email tiktokextensions@gmail.com — free webmail, no business domain, name references TikTok unrelated to product.
  • install_url_hijack manifest onInstalled opens https://swaponline.notion.site/YouTube-Booster-... — 3rd-party redirect on install.
  • generic_privacy_policy store Privacy URL is Google's account policy (myaccount.google.com), not extension-specific; scope_extension=false, data_collection=true, third_party_sharing=true.
  • remote_js_hosts crx js_external_hosts: api.ipify.org, raw.githubusercontent.com, swaponline.notion.site — three distinct external endpoints.
  • csp_absent manifest content_security_policy is null; MV3 default applies but extension fetches remote resources dynamically.
  • title_name_mismatch store Title is 'StreamTube Proxy', developer name is 'tiktokextensions', install redirect mentions 'YouTube Booster' — identity confusion.
  • manifest_localized_strings manifest manifest_name and manifest_description use __MSG_ placeholders — actual description not inspectable from manifest.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers; extremely high-impact.
  • storage low Local extension data storage; minimal standalone risk.
  • https://www.youtube.com/* medium Host access to YouTube; scoped but allows content injection/reading on that site.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 16:10
Listing SHA 5fe6a72cfad6…
Force block — not fired
Score recovered no
Elapsed