Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Happ ВПН-Безапасное соединение

ijilplnnjkjklkmhbklfnpnlnjpbfaie
Risk Score
5.55
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 40
Rating 1.0
Last updated 2026-06-27 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer aslikap21@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full rerouting of browser traffic through unknown servers (app.myxavpn.pro, silashield.space)
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing
  • Developer is anonymous (no name, free-webmail gmail, no verified publisher) with only 40 installs
  • JS contacts silashield.space and t.me — unrecognized/suspicious external hosts outside stated VPN function
  • Install URL hijack detected; low install count + HIGH permission = tail-attack-surface anomaly

Evidence

  • proxy_permission manifest proxy declared — allows complete redirection of all browser network traffic to arbitrary servers.
  • anonymous_developer store No developer name, free-webmail email (aslikap21@gmail.com), not verified, not featured.
  • generic_privacy_policy store Privacy URL points to Google's own account policy (myaccount.google.com/privacypolicy) — not extension-scoped.
  • suspicious_external_hosts crx JS contacts silashield.space and t.me in addition to dns/cloudflare endpoints; silashield.space is unverifiable.
  • install_url_hijack crx install_url_hijack == true; extension opens external URL on installation.
  • small_install_high_perm api Only 40 installs with HIGH-tier proxy permission — tail-attack-surface anomaly flagged.
  • geo_diversity api JS hosts span 4 countries: CA, NL, RU, US — RU-hosted endpoint notable for VPN exfil risk.
  • low_rating store Rating of 1.0 with only 40 installs; no positive trust signals.

Permissions Breakdown

  • proxy high Full proxy control allows rerouting all browser traffic through attacker-controlled servers.
  • host: https://cloudflare-dns.com/* medium DNS-over-HTTPS endpoint; legitimate for VPN but combined with proxy is high-risk surface.
  • host: https://dns.google/* medium DNS-over-HTTPS endpoint; legitimate for VPN but combined with proxy is high-risk surface.

Pillar Scores

Permissions7.00
Reputation8.00
Network5.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:20
Listing SHA 8deaea22695f…
Force block — not fired
Score recovered no
Elapsed