Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Vector VPN — простое подключение в один клик

jdpnclabfdjckoggcihhcfphomgcmfib
Risk Score
5.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 4
Rating 5.0
Last updated 2026-06-11 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer binoyihe32@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through ironproxy.space/myxavpn.pro — unverified Russian-hosted endpoints
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — admits broad sharing with no extension scope
  • Free-webmail dev (binoyihe32@gmail.com), no developer name, no verified publisher — near-zero accountability
  • Install URL hijack opens ironproxy.space on install; JS contacts app.myxavpn.pro, ironproxy.space, t.me — 3 distinct external hosts
  • 4 installs with high-tier proxy permission flags tail-attack-surface anomaly; unknown actors could target enterprise installs

Evidence

  • proxy_permission manifest proxy declared — full traffic interception possible through ironproxy.space and app.myxavpn.pro (NL/RU hosted).
  • install_url_hijack crx onInstalled opens https://ironproxy.space/ — third-party domain not controlled by a verified developer.
  • generic_privacy_policy store Privacy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies → +10.0.
  • free_webmail_no_devname store Dev email binoyihe32@gmail.com, developer_name empty, not verified publisher → Reputation floor >=7.5.
  • js_external_hosts crx 3 external hosts: app.myxavpn.pro, ironproxy.space, t.me. Countries: NL, RU (country_count=2).
  • install_perm_anomaly api 4 installs, has_high_tier_permission=true, small_install_high_perm=true.
  • no_csp manifest csp_present=false on MV3; no content_security_policy declared.
  • cve_findings_empty crx No CVEs found in bundled libraries; cve_findings_raw is empty.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers; full network interception capability.

Pillar Scores

Permissions6.50
Reputation8.00
Network4.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:44
Listing SHA c07b7ef98480…
Force block — not fired
Score recovered no
Elapsed