Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN Cloak

kclcmhakfncbaklinnijihiinbkoajed
Risk Score
6.07
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs
Rating 4.9
Last updated 2026-06-22 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer milumepid39@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through stealthpath.space — unknown Russian-affiliated infrastructure (hosts in RU/NL/CA/US).
  • Developer is anonymous gmail user (milumepid39@gmail.com) with no name, no verified publisher, no business identity.
  • Privacy policy is Google's own policy — entirely unscoped to this extension; ADMITS data collection + third-party sharing by Google, not the extension operator.
  • install_url_hijack opens stealthpath.space on install; JS contacts app.myxavpn.pro and t.me — two undisclosed external domains.
  • No CSP on MV3 extension with proxy capability and 4 distinct external JS hosts including Telegram (t.me).

Evidence

  • proxy_permission manifest proxy declared — full traffic interception capability with no verified operator identity.
  • install_url_hijack crx onInstalled opens https://stealthpath.space/ — affiliate/tracking redirect on install.
  • anonymous_gmail_dev store milumepid39@gmail.com, no developer name, not verified publisher, not featured.
  • generic_google_privacy_policy store Privacy policy is Google account policy — scope_extension=false, data_collection=true, third_party_sharing=true.
  • external_js_hosts crx JS contacts app.myxavpn.pro and t.me — undisclosed endpoints not in host_permissions.
  • geo_diversity api JS hosts span 4 countries: CA, NL, RU, US — Russia-hosted infrastructure for a proxy extension.
  • no_csp manifest content_security_policy null; MV3 default applies but no explicit CSP with broad network reach.
  • description_russian store Description in Russian: 'скрытый proxy для Chrome с режимом невидимого подключения' — narrow Russian-market targeting.

Permissions Breakdown

  • proxy high Full proxy control — can silently reroute all browser traffic through attacker-controlled infrastructure.
  • https://stealthpath.space/* high Unknown third-party domain; install_url_hijack target; single dev-controlled host receiving proxy config.
  • https://cloudflare-dns.com/* low DNS-over-HTTPS endpoint; legitimate for VPN/proxy DNS resolution.
  • https://dns.google/* low DNS-over-HTTPS endpoint; legitimate for VPN/proxy DNS resolution.

Pillar Scores

Permissions7.00
Reputation8.50
Network5.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:48
Listing SHA 69ea817466cf…
Force block — not fired
Score recovered no
Elapsed