Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Storm VPN — скорость без лишних настроек

inddaiiphfojbihdabkdnlpjehfkklhp
Risk Score
5.69
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 10
Rating 5.0
Last updated 2026-06-19 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer binoyihe32@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception/redirection to shieldtunnel.space, an unknown third-party domain.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing (+10 privacy).
  • Install URL hijack redirects to shieldtunnel.space on install; unknown operator behind this domain.
  • Free-webmail Gmail dev account, no developer name, no verified publisher — anonymous operator.
  • External JS host app.myxavpn.pro contacts Russian-geolocated infra; host_geo_diversity spans CA/NL/RU/US.

Evidence

  • proxy_permission manifest proxy declared — can reroute 100% of browser traffic; VPN category gives justified discount but dev is unverified.
  • install_url_hijack store onInstalled opens https://shieldtunnel.space/ — unknown third-party domain, install-time redirect.
  • generic_privacy_policy store Privacy policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → score +10.
  • anonymous_developer store developer_name empty, email binoyihe32@gmail.com (free webmail), no verified publisher badge.
  • external_hosts_suspicious crx JS contacts app.myxavpn.pro, shieldtunnel.space, t.me — 5 external hosts including Telegram and unknown VPN backends.
  • host_geo_diversity api JS hosts span 4 countries: CA, NL, RU, US — +1.5 network penalty for non-VPN-exempt geo diversity under VPN category.
  • small_install_high_perm store Only 10 installs with HIGH-tier proxy permission — tail-attack-surface anomaly (+1.5 webstore).
  • install_url_hijack_webstore store install_url_hijack=true triggers +2.0 webstore signal per rubric.

Permissions Breakdown

  • proxy high proxy is HIGH-impact: can redirect all browser traffic through attacker-controlled server.
  • https://cloudflare-dns.com/* medium Host permission for DNS-over-HTTPS; legitimate for VPN but also enables DNS interception.
  • https://dns.google/* medium Host permission for Google DoH; legitimate for VPN use, low additional risk.

Pillar Scores

Permissions7.00
Reputation7.50
Network5.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:09
Listing SHA 4b7f55791ea0…
Force block — not fired
Score recovered no
Elapsed