Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Дядя Ваня ВПН — серверы рядом

fgnnpafmckdabkmgopdkkcnmenfmahkm
Risk Score
5.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs
Rating 5.0
Last updated 2026-07-24 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer imawocigi29@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception/redirection through neoncloak.space and app.myxavpn.pro (RU/NL hosted)
  • install_url_hijack opens neoncloak.space on install — third-party affiliate/tracking redirect
  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection and 3rd-party sharing) — worst-case privacy disclosure
  • Developer is anonymous free-webmail (gmail), no developer name, no verified publisher status
  • External JS hosts include neoncloak.space and t.me (Telegram); no CSP enforced

Evidence

  • install_url_hijack crx onInstalled opens https://neoncloak.space/ — third-party domain used for tracking/affiliate on install.
  • proxy_permission manifest proxy declared — can redirect all browser traffic through arbitrary servers including neoncloak.space and app.myxavpn.pro.
  • external_js_hosts crx JS contacts app.myxavpn.pro (RU), neoncloak.space (NL), t.me — 3 distinct foreign registrable domains.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true. Not scoped to this extension.
  • no_csp manifest content_security_policy is null; csp_present=false. No script-src restriction on MV3 extension.
  • anonymous_developer store developer_name empty, free-webmail email imawocigi29@gmail.com, no verified publisher badge.
  • geo_diversity api JS hosts span NL and RU — two jurisdictions including Russia for a VPN product.
  • no_install_count store Install count not available; tail-attack surface cannot be ruled out for a high-capability VPN extension.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers — core VPN capability but extremely dangerous if malicious.

Pillar Scores

Permissions5.50
Reputation7.50
Network4.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:09
Listing SHA 1a5b5403e1e0…
Force block — not fired
Score recovered no
Elapsed