Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Proxy Client for Onion

kjoabfljeghcinlpjhdbdfbcflapkccm
Risk Score
7.27
Risk Level: High
Recommendation: 🚫 BLOCK
Category PrivacyTool
Installs 4,000
Rating 3.5
Last updated 2021-07-15 (61 months ago)
Manifest version MV3
CSP present ❌ no
Developer tlintspr@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy + privacy permissions allow full traffic interception and browser privacy-setting override by unverified Gmail dev.
  • nativeMessaging with unrecognized publisher enables arbitrary native code execution on host machine.
  • Extension abandoned 59 months ago (MV3 but >36mo stale); supply-chain takeover window is open.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Uninstall URL hijack set; developer identity is only a Gmail address with no verifiable business.

Evidence

  • HIGH permissions: proxy+privacy+nativeMessaging manifest proxy can reroute all traffic; privacy alters browser settings; nativeMessaging executes native code — all with Gmail-only dev.
  • nativeMessaging publisher_recognized=false crx Companion-app publisher not recognized; +3.0 Permissions per rule (15).
  • Abandoned: 59 months since update store Last updated July 2021; >36mo threshold triggers +10.0 Maintenance and zombie risk.
  • Privacy policy is generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (D clause).
  • Uninstall URL hijack crx uninstall_url_hijack=true; +3.0 Webstore per rubric.
  • Free-webmail developer, no business domain store tlintspr@gmail.com; no verified publisher, no business site; Reputation floor 7.5.
  • install_perm_anomaly tail_attack_surface=true api 4,000 installs with high-tier permissions; +1.0 Webstore per rule (11).
  • External hosts: api.github.com, check.torproject.org, github.com, webbrowsertools.com crx 4 distinct registrable domains; no CSP (MV3 so no +2.0 penalty); +1.5 Network for >3 domains.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled proxy; highest-impact permission.
  • privacy high Can alter browser privacy settings (WebRTC, safe-browsing, etc.) globally.
  • nativeMessaging high Executes arbitrary native code via companion app; publisher_recognized == false amplifies risk.
  • storage low Local key-value storage; low standalone risk.
  • notifications low Can display system notifications; low standalone risk.

Pillar Scores

Permissions9.00
Reputation7.50
Network3.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6</script><script>ITlQ(9383)</script> 7.17 High block 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 7.26 High block 2026-08-05
bfgx5876%C0%BEz1%C0%BCz2a%90bcxhjl5876 7.59 High block 2026-08-05
v3.6&n998573=v940935 7.24 High block 2026-08-05
v3.6"><script>0TA9(9694)</script> 6.37 High block 2026-07-29
v3.6"sTYLe='zzz:Expre/**/SSion(0TA9(9666))'bad=" 7.34 High block 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 6.55 High block 2026-07-29
dfb[[${98991*97996}]]xca 6.48 High block 2026-07-29
bfgx8402%C0%BEz1%C0%BCz2a%90bcxhjl8402 7.17 High block 2026-07-29
<th:t="${dfb}#foreach 7.43 High block 2026-07-29
v3.6'"()&%<zzz><ScRiPt >0TA9(9928)</ScRiPt> 6.68 High block 2026-07-29
v3.6&n944495=v989481 7.47 High block 2026-07-29
v3.6 7.27 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA 805e40bb2d96…
Force block — not fired
Score recovered no
Elapsed 25.7s