Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kit Vpn

hpgghhpnkoamfbhiihfachccnkdlkiog
Risk Score
8.12
Risk Level: Critical
Recommendation: 🚫 BLOCK
Category VPN
Installs 10
Rating 4.9
Last updated 2026-06-12 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer norkienej@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception/redirection through attacker-controlled servers (maskirovka.space, app.myxavpn.pro, RU-hosted).
  • Install URL hijack opens maskirovka.space on install — classic ad/phishing redirect pattern.
  • Privacy policy is Google's own policy (not scoped to this extension); admits data collection and 3rd-party sharing — D clause triggers +10.0.
  • Free webmail dev (gmail), no developer name, 6 installs with high-capability permission — tail-attack-surface fingerprint.
  • JS external hosts include maskirovka.space (RU) and t.me (Telegram) alongside VPN backend — unusual for legitimate VPN.

Evidence

  • proxy_permission manifest proxy declared; enables full traffic rerouting through maskirovka.space / app.myxavpn.pro.
  • install_url_hijack crx onInstalled opens https://maskirovka.space — 3rd-party site, not developer's store page.
  • external_hosts crx JS contacts app.myxavpn.pro (NL), maskirovka.space (RU), t.me — 3 distinct domains.
  • privacy_policy_generic store Policy is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store No developer name; free Gmail address norkienej@gmail.com; 6 installs; not verified.
  • geo_diversity api Hosts span NL and RU — RU-hosted VPN backend with maskirovka.space (maskirovka = camouflage in Russian).
  • install_perm_anomaly api small_install_high_perm=true: 6 installs + proxy permission is a tail-attack-surface fingerprint.
  • csp_absent manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through arbitrary servers; full MITM capability if abused.

Pillar Scores

Permissions7.50
Reputation7.50
Network4.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiednb7260b16dp727562726963xsx 5.49 Medium block 2026-09-09
v3.6 8.12 Critical block 2026-09-02

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:31
Listing SHA d817d67d4a0d…
Force block — not fired
Score recovered no
Elapsed