Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN-мост

hoeghcokeoglleffagcmajogjkgeinjc
Risk Score
5.22
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 6
Rating 4.3
Last updated 2026-06-19 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer vale99505@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission with unknown backend (stealthpath.space) can route all browser traffic through unverifiable server
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing
  • Developer is anonymous (no name, free Gmail, no business website) with only 6 installs — low accountability
  • install_url_hijack opens stealthpath.space on install — unsolicited navigation to unknown third party
  • small_install + high-perm anomaly: only 6 users but holds proxy capability — tail attack surface risk

Evidence

  • proxy_permission manifest proxy declared; can redirect all browser traffic to stealthpath.space controlled by unknown developer
  • install_url_hijack store install_url_target=https://stealthpath.space/ — opens 3rd-party site on install
  • privacy_policy_generic store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores 10.0
  • anonymous_developer store developer_name empty, email=vale99505@gmail.com (free webmail), no verified publisher, no business domain
  • install_perm_anomaly api 6 installs + proxy permission = small_install_high_perm=true
  • host_geo_diversity api JS hosts span 3 countries (CA, RU, US); RU-hosted backend for VPN raises jurisdiction concern
  • csp_absent manifest csp_present=false on MV3; +2.0 network per v2 calibration (MV2+no CSP rule does not apply but noted absent)
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0 — 2 JS files scanned with no detected malicious patterns

Permissions Breakdown

  • proxy high Proxy permission can redirect all browser traffic through attacker-controlled servers.
  • https://stealthpath.space/* high Unknown domain; VPN backend operated by unverifiable developer.
  • https://cloudflare-dns.com/* low Cloudflare public DNS — legitimate for DoH resolution in VPN context.
  • https://dns.google/* low Google public DNS — legitimate for DoH resolution in VPN context.

Pillar Scores

Permissions5.50
Reputation7.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:32
Listing SHA d3d409aba4b5…
Force block — not fired
Score recovered no
Elapsed