Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN 999 - Auto change IP per minute

heangbenngmkonmlfhhgopehajjfifgd
Risk Score
6.26
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 335
Rating 1.8
Last updated 2025-03-24 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer otpmailteam@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Proxy permission allows complete rerouting of browser traffic through unverified operator-controlled servers.
  • Privacy policy is Google's generic account policy — does not scope to this extension, fetched with data_collection+third_party_sharing true.
  • Gmail developer email (otpmailteam@gmail.com) with no verifiable business identity or domain.
  • Low rating (1.8) on a VPN extension with very few installs signals potential non-functional or malicious behavior.
  • install_perm_anomaly: small-install + high-permission combo indicates tail attack surface.

Evidence

  • proxy_permission manifest proxy declared — full browser traffic routing capability, highest-risk VPN permission.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email otpmailteam@gmail.com, no associated business domain; developer_domain_info null.
  • low_rating store Rating 1.8 on a proxy/VPN extension with only 335 installs.
  • no_csp manifest content_security_policy is null (MV3, so no MV2 penalty, but no CSP increases DOM-sink risk).
  • install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 335 installs with proxy permission.
  • maintenance_stale store 15 months since update; falls in 12-24 month band (+6.0 maintenance score).
  • external_api_host crx js_external_hosts includes vpn.api999.com — unverified dev-controlled endpoint for proxy ops.

Permissions Breakdown

  • proxy high Full proxy control lets extension route all browser traffic through arbitrary servers.
  • storage low Local data persistence only; low standalone risk.
  • alarms low Periodic execution for IP rotation; low standalone risk.
  • https://vpn.api999.com/* high Scoped host permission to unverified dev-controlled API endpoint for proxy configuration.

Pillar Scores

Permissions6.50
Reputation7.50
Network4.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA f072a35599fe…
Force block — not fired
Score recovered no
Elapsed 20.2s