Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Proton VPN — Безопасный доступ

ihldefkgpnceoelikkacpffhabnhfdpm
Risk Score
6.79
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 32
Rating 5.0
Last updated 2026-06-15 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer imawocigi29@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Impersonates Proton VPN brand — dev is gmail user with no affiliation; proxy permission enables full traffic interception.
  • Install hijack opens primeproxy.space on install — unknown third-party monetization/phishing destination.
  • Privacy policy is Google's own policy (not scoped to this extension); data_collection and third_party_sharing both true.
  • Free-webmail dev (imawocigi29@gmail.com), no developer name, no verified publisher — zero accountability.
  • JS contacts app.myxavpn.pro and primeproxy.space — unrecognized proxy infrastructure in NL/RU geo diversity.

Evidence

  • brand_impersonation store Title 'Proton VPN' used by gmail dev imawocigi29@gmail.com; brand_mention.confirmed_owner=false; not verified publisher.
  • install_url_hijack manifest onInstalled opens https://primeproxy.space/ — third-party unknown domain, monetization/phishing risk.
  • proxy_permission manifest proxy permission declared — can redirect all browser traffic through attacker-controlled endpoints.
  • free_webmail_no_devname store Developer email imawocigi29@gmail.com, developer_name empty, no verified publisher, no business website.
  • generic_google_privacy_policy api Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
  • external_js_hosts crx JS contacts app.myxavpn.pro, primeproxy.space, t.me — unrecognized proxy infra; geo: NL, RU.
  • small_install_high_perm store Only 32 installs with HIGH-tier proxy permission — tail attack surface anomaly flagged.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.

Permissions Breakdown

  • proxy high Can route all browser traffic through attacker-controlled servers, enabling full traffic interception.

Pillar Scores

Permissions8.00
Reputation9.50
Network4.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:03
Listing SHA a8cc04c9d054…
Force block — not fired
Score recovered no
Elapsed