Открытый VPN
hkknofgppcaphiolocpkdljneopbmccf
Risk Score
4.25
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes all browser traffic through stealthpath.space — unverified, low-install operator with free-webmail dev identity.
- Install-URL hijack: onInstalled opens stealthpath.space, a third-party domain not controlled by a verified publisher.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer: no name, free Gmail address, no verified publisher badge — zero accountability for a traffic-intercepting extension.
- Only 52 installs with a HIGH-tier permission (proxy) signals tail-attack-surface risk; small install base hides abuse.
Evidence
- proxy_permission manifest proxy declared — can silently reroute all HTTP/HTTPS traffic through stealthpath.space.
- install_url_hijack crx install_url_hijack=true targeting https://stealthpath.space/ — third-party redirect on install.
- free_webmail_no_dev_name store developer_email=milumepid39@gmail.com, developer_name empty, no verified publisher badge.
- generic_google_privacy_policy store Privacy policy is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
- small_install_high_perm api 52 installs with proxy (HIGH) permission — install_perm_anomaly.small_install_high_perm=true.
- host_geo_russia crx js_external_hosts include stealthpath.space hosted in RU — elevated jurisdiction risk for traffic interception.
- no_csp manifest csp_present=false; MV3 provides some default protection but no explicit policy declared.
- cve_findings_clean crx cve_findings_raw empty; no library CVEs detected.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled server; full network interception capability.
- https://stealthpath.space/* high Unknown third-party domain used as VPN backend; install-URL hijack target; unverified operator.
- https://cloudflare-dns.com/* low DoH provider access; expected for VPN DNS leak prevention.
- https://dns.google/* low Google DoH access; expected for DNS resolution in VPN context.
Pillar Scores
Permissions7.50
Reputation7.50
Network2.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:04
Listing SHA
38fa25b8a2c9…
Force block
— not fired
Score recovered
no
Elapsed
—