Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ПаукНет – ВПН для РФ

fhggcomokafcmghkeknnoogghkkalchb
Risk Score
4.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 160
Rating 5.0
Last updated 2026-05-08 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer oveyila408@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic; free-webmail dev with no verified identity could redirect to malicious endpoints
  • Privacy policy URL returns fetch error (HTTP error) — policy unverifiable; privacy pillar scores maximum penalty
  • Free-webmail developer (gmail) with no developer name and no business website — no accountability
  • install_url_hijack: onInstalled opens a third-party URL (Telegram t.me link) — covert install-time redirect
  • Small install count (160) with high-impact permission (proxy) matches tail-attack-surface anomaly pattern

Evidence

  • proxy_permission manifest proxy declared; VPN category matches function but developer identity is unverified free-webmail account.
  • install_url_hijack store install_url_hijack=true; onInstalled opens external URL. js_external_hosts=[t.me] confirms Telegram redirect.
  • privacy_policy_fetch_failed api Privacy policy at spidervpn.online/privacy returned HTTPError; policy content unverifiable — max privacy penalty.
  • free_webmail_no_dev_name store developer_email=oveyila408@gmail.com; developer_name empty; no verified publisher; no business website.
  • small_install_high_perm store 160 installs + proxy (HIGH permission) = install_perm_anomaly.small_install_high_perm=true.
  • no_csp manifest content_security_policy=null; MV3 has strict default so no additional penalty applied.
  • no_cve_findings crx cve_findings_raw empty; js_libraries_detected empty; CVE pillar=0.
  • obfuscation_clean crx obfuscation_score=0.0; code_findings_raw empty; 5 JS files scanned cleanly.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers; core VPN risk.
  • storage low Stores local config/settings; low standalone risk.
  • activeTab low Transient access to current tab on user action; limited scope.

Pillar Scores

Permissions4.50
Reputation8.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:54
Listing SHA 2b39e5a20f92…
Force block — not fired
Score recovered no
Elapsed