VPN-зонт
falfcccfjmagebegdiaoiimndpdlmihh
Risk Score
4.47
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission routes all browser traffic through attacker-controlled stealthpath.space infrastructure.
- Privacy policy is Google's generic account policy—does not scope data collection to this extension at all.
- install_url_hijack opens stealthpath.space on install; unknown third-party monetization/tracking destination.
- Free-webmail dev (jomcna56@gmail.com), no developer name, no business website—unverifiable identity.
- JS contacts stealthpath.space + cloudflare-dns.com + dns.google; RU geo node among hosting countries.
Evidence
- proxy_permission manifest Single HIGH permission 'proxy' grants full control over browser network routing.
- install_url_hijack store onInstalled opens https://stealthpath.space/ — unknown third-party domain, monetization unknown.
- generic_google_privacy_policy store Privacy URL is Google account policy (479 KB); scope_extension=false, not scoped to this extension.
- free_webmail_no_devname store Developer email jomcna56@gmail.com, no developer name — unverifiable identity per rubric floor ≥7.5.
- external_hosts crx JS contacts stealthpath.space, cloudflare-dns.com, dns.google — 3 distinct domains.
- geo_diversity api Hosting countries: CA, RU, US — RU node present for a VPN proxy service.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP set.
- privacy_policy_data_collection_third_party store Fetched policy: data_collection=true, third_party_sharing=true, scope_extension=false → +10.0 privacy.
Permissions Breakdown
- proxy high Allows full rerouting of browser traffic; highest-impact VPN-class permission.
Pillar Scores
Permissions2.00
Reputation8.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:18
Listing SHA
d85dd699f42d…
Force block
— not fired
Score recovered
no
Elapsed
—