Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Протон VPN

hhebjfghjolapmbfpjeppcchgglanfgh
Risk Score
6.17
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 20
Rating 4.9
Last updated 2026-05-28 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer imawocigi29@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission gives full network traffic interception capability to unverified free-webmail developer
  • Privacy policy is Google's generic policy — not scoped to this extension, data collection and 3rd-party sharing admitted
  • install_url_hijack: onInstalled opens 3rd-party URL (app.getmyxa.com) — monetization/tracking shell pattern
  • Developer is anonymous (no name, free Gmail, no business domain) with only 20 installs — tail attack surface
  • External JS host app.getmyxa.com (NL/RU geo) unknown; proxy extension contacting unknown host is critical risk

Evidence

  • proxy_permission_high_risk manifest proxy declared — routes all browser traffic through extension-controlled servers; extremely high capability for anonymous dev.
  • install_url_hijack store install_url_hijack=true targeting app.getmyxa.com; monetization/tracking shell behavior on install.
  • free_webmail_no_dev_name store Developer email imawocigi29@gmail.com, no developer name, no business domain — reputation floor triggered.
  • generic_google_privacy_policy store Privacy policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • external_js_hosts crx JS contacts app.getmyxa.com (NL/RU) and t.me; unknown third-party endpoints for a VPN extension.
  • small_install_high_perm store Only 20 installs with HIGH-tier proxy permission — tail attack surface anomaly flagged.
  • no_csp manifest content_security_policy is null; MV3 has strict defaults but absence still notable alongside external hosts.
  • brand_impersonation_risk store Title 'Протон VPN' mimics ProtonVPN brand; brand_mention.is_impersonation=false per classifier but unverified dev uses brand name.

Permissions Breakdown

  • proxy high Full control over all browser network traffic; can redirect all requests to attacker-controlled servers.

Pillar Scores

Permissions7.00
Reputation8.50
Network3.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:11
Listing SHA 849824ccf7f0…
Force block — not fired
Score recovered no
Elapsed