Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Борщ VPN

ihbmgokcocjiihdmjkeblefcpbgeefkk
Risk Score
4.32
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 16
Rating 5.0
Last updated 2026-04-24 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer norkienej@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through gusentun.space — unverified Russian-hosted server, high MITM risk
  • Install URL hijack opens gusentun.space on install — active C2/tracking beacon pattern
  • Privacy policy is Google's generic account policy, wholly unscoped to this extension — admits data collection and 3rd-party sharing
  • Free-webmail dev (gmail), no developer name, no verified publisher — zero accountability
  • MV3 + no CSP + proxy: high-capability extension with no content security controls and only 16 installs

Evidence

  • proxy_permission manifest proxy declared — full network interception capability; all traffic can be tunneled to gusentun.space (RU-hosted).
  • install_url_hijack crx onInstalled opens https://gusentun.space — third-party domain, typical C2 beacon or affiliate-registration pattern.
  • js_external_host crx gusentun.space is the sole external JS host; single RU-country endpoint for a VPN extension.
  • privacy_policy_generic store Policy URL is Google Account policy (479 KB); scope_extension=false, data_collection=true, third_party_sharing=true — D clause triggers +10.
  • free_webmail_no_devname store Developer email norkienej@gmail.com, developer_name empty, no verified publisher — reputation floor applies.
  • small_install_high_perm api install_perm_anomaly: 16 installs with HIGH-tier proxy permission — tail attack surface.
  • no_csp manifest csp_present=false on MV3; v2 fix (b) adds +2.0 Network for MV2 only, but absence still noted as risk indicator.
  • geo_diversity crx All JS hosts in RU only; VPN routing to single unverified Russian endpoint.

Permissions Breakdown

  • proxy high Full proxy control — can intercept and redirect all network traffic through attacker-controlled servers.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:45
Listing SHA 97d591d91862…
Force block — not fired
Score recovered no
Elapsed