Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Decodo(Smartproxy) Extension

hdemabfejemmmicoabglpocdmmkjphpo
Risk Score
4.00
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 30,000
Rating 4.4
Last updated 2026-06-15
Manifest version MV3
CSP present ❌ no
Developer support@decodo.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Proxy+cookies+browsingData+<all_urls> combo gives full traffic interception and session-hijack capability.
  • Privacy policy (smartproxy.com) is not scoped to this extension and admits third-party data sharing.
  • No CSP on MV3 extension with 10 external JS hosts including bit.ly (affiliate/cloaking link).
  • Developer name field empty; policy domain (smartproxy.com) differs from extension branding (decodo.com).
  • Geo-diverse JS hosts (4 countries: CA, DE, IN, US) increases supply-chain attack surface.

Evidence

  • HIGH permission cluster manifest proxy+webRequest+webRequestAuthProvider+browsingData+cookies+privacy+<all_urls> — maximum traffic and session access.
  • No CSP declared crx content_security_policy is null on MV3; +2.0 network penalty applied per v2 calibration.
  • affiliate_hits: bit.ly api bit.ly listed as generic short-link redirector / affiliate cloaking in threat_intel.
  • Privacy policy not extension-scoped store policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • Verified publisher + featured by Google store Both signals present; caps reputation floor at 2.0 after discounts.
  • Geo-diversity: 4 countries api JS hosts span CA, DE, IN, US; +1.5 network per rule (14), category VPN exempt — not applied.
  • No code findings / obfuscation crx obfuscation_score=0.0, code_findings_raw=[], code quality pillar = 0.00.
  • 10 external JS hosts including developer docs crx addons.mozilla.org, github.com, reactjs.org, redux.js.org etc — >3 distinct domains, +1.5 network.

Permissions Breakdown

  • proxy high Routes all browser traffic through attacker-controlled endpoint if compromised.
  • webRequest high Can observe all HTTP/S requests across every site.
  • webRequestAuthProvider high Intercepts and supplies proxy authentication credentials.
  • browsingData high Can delete cookies, cache, history — broad destructive capability.
  • cookies high Read/write cookies for all sites; combined with <all_urls> is critical.
  • privacy high Can alter browser privacy settings (WebRTC, referrers, etc.).
  • tabs medium Reads tab URLs and metadata across all open tabs.
  • storage low Local extension data storage; low standalone risk.
  • <all_urls> high Host permission covering every URL; amplifies all other high permissions.

Pillar Scores

Permissions6.50
Reputation2.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA e423b0055ef6…
Force block — not fired
Score recovered no
Elapsed 26.0s