Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Open VPN — свободный доступ

iloeambbfeeikpjhkpfcbcplpobgapel
Risk Score
5.39
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 81
Rating 5.0
Last updated 2026-07-22 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer sedatkilli87@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through developer-controlled servers (neoncloak.space, app.myxavpn.pro)
  • Install-URL hijack opens neoncloak.space on installation — classic monetization/tracking shell pattern
  • Privacy policy is Google's generic policy, not scoped to this extension; data collection + 3rd-party sharing admitted
  • Free-webmail developer (Gmail), no developer name, no verifiable business identity
  • JS phones home to neoncloak.space and app.myxavpn.pro hosted in NL+RU — elevated geopolitical risk for proxy traffic

Evidence

  • proxy_permission manifest proxy declared — full control over browser network routing; VPN category partially justifies but trust chain unverifiable.
  • install_url_hijack crx onInstalled opens https://neoncloak.space/ — same domain as JS external host; monetization/tracking shell indicator.
  • external_js_hosts crx JS contacts app.myxavpn.pro, neoncloak.space, t.me — 3 distinct domains; NL+RU geo hosting.
  • privacy_policy_generic store Policy URL is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • reputation_freeweb_no_devname store Developer email sedatkilli87@gmail.com (free webmail), developer_name empty, no verified publisher, not featured.
  • small_install_high_perm api Only 81 installs with HIGH-tier proxy permission — install_perm_anomaly.small_install_high_perm=true.
  • no_csp manifest content_security_policy is null; MV3 default applies but extension contacts 3 external domains dynamically.
  • geo_diversity crx JS hosts span NL and RU (country_count=2); RU-hosted proxy infrastructure elevates traffic interception risk.

Permissions Breakdown

  • proxy high Full browser proxy control — can route all traffic through attacker-chosen servers.

Pillar Scores

Permissions6.00
Reputation8.00
Network3.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:27
Listing SHA d4ac89173177…
Force block — not fired
Score recovered no
Elapsed