ВПН для Ютуб
fephkdkjkfcciljffkakepiefhmeikpm
Risk Score
6.02
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes ALL browser traffic through zhuknet.online — complete MITM capability.
- Install URL hijack opens zhuknet.online on install; external JS also loaded from same domain.
- Privacy policy is Google's generic policy; not scoped to this extension; admits data collection and 3rd-party sharing.
- Developer is free-webmail only (gmail), no name, no verified publisher — unaccountable operator.
- 78 installs with HIGH-tier proxy permission: tail-attack-surface anomaly.
Evidence
- proxy_permission manifest proxy declared — can redirect all browser network traffic to any server the extension chooses.
- install_url_hijack crx onInstalled opens https://zhuknet.online — same domain as external JS host; monetization/tracking likely.
- external_js_host crx js_external_hosts: [zhuknet.online] — single external domain matches install hijack target.
- privacy_policy_generic store Policy is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- free_webmail_no_name store Developer email oveyila408@gmail.com; developer_name empty; no verified publisher; no business identity.
- small_install_high_perm api install_perm_anomaly: 78 installs + proxy (HIGH-tier) — tail attack surface anomaly confirmed.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with external host contacts.
- host_geo api All JS hosts geolocate to RU (Russia); single country; aligns with zhuknet.online external host.
Permissions Breakdown
- proxy high Full proxy control allows routing all browser traffic through attacker-controlled infrastructure.
Pillar Scores
Permissions7.00
Reputation8.00
Network4.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:53
Listing SHA
fe1c1acd0505…
Force block
— not fired
Score recovered
no
Elapsed
—