Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Irisska Tunnel — Быстрый VPN Прокси

gaijfdefjhclenikcaggjoblodfchmge
Risk Score
4.57
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 26
Rating 5.0
Last updated 2026-04-15 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer kameqoko032@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through korovkavpn.space — a single unverified Russian-hosted server with no accountability.
  • Privacy policy is Google's generic account policy; does not scope to this extension, admits data collection and 3rd-party sharing — worst-case privacy signal.
  • Developer is a free-webmail anonymous account (kameqoko032@gmail.com) with no name, no verified publisher status.
  • install_url_hijack active: extension opens a 3rd-party URL on install, a common monetization/tracking pattern.
  • Very low install count (26) + HIGH capability (proxy) matches tail-attack-surface anomaly; possible targeted deployment.

Evidence

  • proxy_permission manifest proxy declared — can intercept and redirect all browser HTTP/HTTPS traffic to korovkavpn.space.
  • external_js_host crx js_external_hosts: ['korovkavpn.space'] — Russian-hosted domain; extension loads or contacts this host.
  • install_url_hijack crx install_url_hijack=true; extension opens a 3rd-party URL on install. Target not captured.
  • generic_privacy_policy store Privacy policy points to Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_anonymous_dev store Developer email kameqoko032@gmail.com, developer_name empty, not verified, not featured.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening.
  • small_install_high_perm api install_perm_anomaly: 26 installs + proxy (HIGH tier) — tail-attack-surface risk flagged.
  • geo_single_country_ru api host_geo_diversity: all JS hosts in RU only; proxy traffic would traverse Russian infrastructure.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; extremely high capability for a VPN.

Pillar Scores

Permissions6.50
Reputation8.50
Network4.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:53
Listing SHA 1861c315b923…
Force block — not fired
Score recovered no
Elapsed