StreamTube Proxy
epkcfhiniijndongcpclcfogmbpphfga
Risk Score
5.68
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission allows full traffic interception/redirection for all browser traffic despite narrow stated scope.
- Developer is a free-webmail Gmail account named 'tiktokextensions' with no verified business identity.
- Privacy policy is Google's own generic policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
- Install URL hijack redirects new installs to a Notion page under an unrelated domain (swaponline.notion.site).
- Extension fetches from raw.githubusercontent.com at runtime — potential for remote code/config injection.
Evidence
- proxy_permission manifest proxy declared; routes all browser traffic — no host-scoping in proxy API regardless of host_permissions.
- free_webmail_dev store Developer email tiktokextensions@gmail.com — free webmail, no business domain, name references TikTok unrelated to product.
- install_url_hijack manifest onInstalled opens https://swaponline.notion.site/YouTube-Booster-... — 3rd-party redirect on install.
- generic_privacy_policy store Privacy URL is Google's account policy (myaccount.google.com), not extension-specific; scope_extension=false, data_collection=true, third_party_sharing=true.
- remote_js_hosts crx js_external_hosts: api.ipify.org, raw.githubusercontent.com, swaponline.notion.site — three distinct external endpoints.
- csp_absent manifest content_security_policy is null; MV3 default applies but extension fetches remote resources dynamically.
- title_name_mismatch store Title is 'StreamTube Proxy', developer name is 'tiktokextensions', install redirect mentions 'YouTube Booster' — identity confusion.
- manifest_localized_strings manifest manifest_name and manifest_description use __MSG_ placeholders — actual description not inspectable from manifest.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled servers; extremely high-impact.
- storage low Local extension data storage; minimal standalone risk.
- https://www.youtube.com/* medium Host access to YouTube; scoped but allows content injection/reading on that site.
Pillar Scores
Permissions7.00
Reputation7.50
Network4.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:10
Listing SHA
5fe6a72cfad6…
Force block
— not fired
Score recovered
no
Elapsed
—