Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Хит VPN

fpiolkbhpmebbdpanjfmnoacpkkdgbel
Risk Score
5.11
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 85
Rating 4.8
Last updated 2026-04-21 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer sedatkilli87@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through usachvpn.su (.su = Soviet Union ccTLD, opaque jurisdiction).
  • Privacy policy is Google's generic policy — does not scope data collection to this extension at all; classified as admitting collection+3rd-party sharing without extension scope → Privacy pillar 10.
  • Developer is anonymous (no name, free Gmail), small install count with high-impact permission flags install_perm_anomaly.
  • install_url_hijack=true: extension opens an external URL on install, classic monetization/tracking vector.
  • No CSP on MV3 is less critical but extension contacts single foreign (.su) JS host with no transparency.

Evidence

  • proxy_permission manifest proxy declared — routes all browser traffic; VPN category partially justifies but anonymous dev + .su host amplifies risk.
  • install_url_hijack crx install_url_hijack=true; extension fires external URL on install — tracking/monetization vector.
  • js_external_host_su crx js_external_hosts=['usachvpn.su']; .su ccTLD with single RU-geolocated host, opaque operator.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy=10.
  • anonymous_developer store developer_name empty, free Gmail (sedatkilli87@gmail.com), not verified publisher, not featured.
  • small_install_high_perm api 85 installs with proxy (HIGH-tier) permission — tail attack surface anomaly flagged.
  • host_geo_diversity crx Single JS host country: RU. Low diversity but all infra in Russia.
  • no_cve_findings crx cve_findings_raw empty; no library CVEs detected.

Permissions Breakdown

  • proxy high Allows full routing of browser traffic through attacker-controlled SOCKS5 servers; high-impact capability.

Pillar Scores

Permissions6.00
Reputation7.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:35
Listing SHA 60a3fc9e2cfc…
Force block — not fired
Score recovered no
Elapsed