Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

STEALTH IP Changer

iodkdijgnghohpafaeolekldgcldompf
Risk Score
6.71
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 85
Rating
Last updated 2025-04-13 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer stlsprendimai@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy + webRequest + <all_urls>: can silently reroute all browser traffic with no verified accountability.
  • Privacy policy is a generic freeprivacypolicy.com template admitting data collection and 3rd-party sharing, not scoped to this extension — scores 10.0.
  • Gmail developer with no verified business domain or publisher badge; small install base with critical permissions is a tail-attack-surface flag.
  • No CSP and content scripts injected on <all_urls> alongside DOM-XSS sink (jquery innerHTML) increases exploitation surface.
  • 12-24 month staleness with high-capability permissions raises future-compromise risk.

Evidence

  • proxy+webRequest+<all_urls> manifest Holds proxy, webRequest, privacy, and <all_urls> — full traffic interception capability with no verified publisher.
  • generic_privacy_policy store Policy on freeprivacypolicy.com: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 (v3.5 D).
  • gmail_dev_no_domain store Developer email stlsprendimai@gmail.com; no business domain, no verified publisher badge.
  • install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; only 85 installs with critical permissions.
  • no_csp crx content_security_policy is null; no CSP present on MV3 extension with external JS hosts.
  • dom_sink_innerhtml crx jquery-3.5.1.js has innerHTML assignment from variable — DOM-XSS sink; no CSP present amplifies risk.
  • js_external_hosts crx 12 external JS hosts including 5.79.109.91 (bare IP) and multiple jquery/webkit CDN references.
  • months_stale store 14 months since last update — falls in 12-24mo band (+6.0 maintenance).

Permissions Breakdown

  • webRequest high Can intercept and observe all HTTP/S traffic across every site.
  • proxy high Full control over network routing; can silently redirect all traffic.
  • privacy high Can alter Chrome privacy settings globally.
  • storage low Local extension data storage; low standalone risk.
  • <all_urls> (host_permission) high Broad host access paired with proxy/webRequest enables full traffic interception.
  • content_scripts <all_urls> high Script injection into every page visited.

Pillar Scores

Permissions8.50
Reputation7.50
Network5.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA 8c6611804372…
Force block — not fired
Score recovered no
Elapsed 25.3s