STEALTH IP Changer
iodkdijgnghohpafaeolekldgcldompf
Risk Score
6.71
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy + webRequest + <all_urls>: can silently reroute all browser traffic with no verified accountability.
- Privacy policy is a generic freeprivacypolicy.com template admitting data collection and 3rd-party sharing, not scoped to this extension — scores 10.0.
- Gmail developer with no verified business domain or publisher badge; small install base with critical permissions is a tail-attack-surface flag.
- No CSP and content scripts injected on <all_urls> alongside DOM-XSS sink (jquery innerHTML) increases exploitation surface.
- 12-24 month staleness with high-capability permissions raises future-compromise risk.
Evidence
- proxy+webRequest+<all_urls> manifest Holds proxy, webRequest, privacy, and <all_urls> — full traffic interception capability with no verified publisher.
- generic_privacy_policy store Policy on freeprivacypolicy.com: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 (v3.5 D).
- gmail_dev_no_domain store Developer email stlsprendimai@gmail.com; no business domain, no verified publisher badge.
- install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; only 85 installs with critical permissions.
- no_csp crx content_security_policy is null; no CSP present on MV3 extension with external JS hosts.
- dom_sink_innerhtml crx jquery-3.5.1.js has innerHTML assignment from variable — DOM-XSS sink; no CSP present amplifies risk.
- js_external_hosts crx 12 external JS hosts including 5.79.109.91 (bare IP) and multiple jquery/webkit CDN references.
- months_stale store 14 months since last update — falls in 12-24mo band (+6.0 maintenance).
Permissions Breakdown
- webRequest high Can intercept and observe all HTTP/S traffic across every site.
- proxy high Full control over network routing; can silently redirect all traffic.
- privacy high Can alter Chrome privacy settings globally.
- storage low Local extension data storage; low standalone risk.
- <all_urls> (host_permission) high Broad host access paired with proxy/webRequest enables full traffic interception.
- content_scripts <all_urls> high Script injection into every page visited.
Pillar Scores
Permissions8.50
Reputation7.50
Network5.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
8c6611804372…
Force block
— not fired
Score recovered
no
Elapsed
25.3s