Moovpn — кибер-прокси для свободной сети
kaonoofcdglmjidkpokanpbjfdbfhamk
Risk Score
5.63
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission routes all browser traffic through korovkavpn.space — single RU-hosted external JS domain with no visibility into server infra
- Privacy policy is Google's own policy, not scoped to this extension; admits data collection and 3rd-party sharing without any extension-specific disclosure
- Developer is unnamed, uses free Gmail, no verified publisher badge, no business website — zero accountability
- install_url_hijack=true: extension opens a URL on install to unknown 3rd-party target
- Only 7 installs with a HIGH-tier permission (proxy) — tail-attack-surface anomaly flagged
Evidence
- proxy_permission manifest proxy declared; all browser TCP connections can be silently redirected to korovkavpn.space (RU-hosted).
- generic_privacy_policy store Privacy URL points to Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — triggers +10.0 Privacy.
- install_url_hijack crx install_url_hijack=true; extension calls onInstalled to open a 3rd-party URL (target not disclosed).
- free_webmail_no_dev_name store developer_name empty, email egositburak@gmail.com — free webmail, no verified business identity.
- external_js_ru_host crx js_external_hosts=['korovkavpn.space']; sole external host is RU-geolocated, unknown ownership.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit policy tightening.
- install_perm_anomaly api 7 installs + proxy permission; small_install_high_perm=true — uncommon tail attack surface.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no trust signals from Google.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled servers; critical for a VPN but also a powerful interception tool.
Pillar Scores
Permissions7.00
Reputation7.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| fsssiedxn3d005d37zafdsaxax><!--></ScRiPt>asddn3d005d37zsssiedx | 5.52 | Medium | block | 2026-09-10 |
| fsssiedxn76213f60za'n76213f60zsssiedx | 5.21 | Medium | review | 2026-09-10 |
| fsssiedxnd999d931za$'nd999d931zsssiedx | 4.48 | Medium | block | 2026-09-10 |
| sssiedn4576a296dp727562726963xsx | 4.54 | Medium | block | 2026-09-10 |
| v3.6 | 5.63 | Medium | block | 2026-09-02 |
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:51
Listing SHA
ad51774c1f4b…
Force block
— not fired
Score recovered
no
Elapsed
—