Салют Proxy
ijpbkjknnkpjnkndfgddfflpoickilmf
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission routes ALL browser traffic through developer-controlled server (usachvpn.su, RU-hosted).
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail dev (gmail), no developer name, no business website — identity unverifiable.
- install_url_hijack: onInstalled fires redirect — behaviour at install time unverified.
- External JS host usachvpn.su (Russia) with no CSP — remote code surface not constrained.
Evidence
- proxy_permission manifest proxy declared; can redirect all browser HTTP/HTTPS/SOCKS traffic to usachvpn.su (RU).
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev_no_name store Developer email egositburak@gmail.com, developer_name empty, no business domain.
- install_url_hijack crx install_url_hijack=true; extension fires onInstalled redirect. Target URL not resolved.
- external_js_host crx js_external_hosts: [usachvpn.su] — RU-hosted; no CSP to constrain remote script execution.
- no_csp manifest csp_present=false on MV3; external JS host amplifies risk without script-src restriction.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals.
- install_count_missing store Install count unavailable; blast radius unknown but small-install + high-perm anomaly flagged.
Permissions Breakdown
- proxy high Full proxy control allows routing all browser traffic through attacker-controlled servers.
Pillar Scores
Permissions7.00
Reputation8.00
Network3.50
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:36
Listing SHA
0f1f8caf00ec…
Force block
— not fired
Score recovered
no
Elapsed
—