Proxy Client for Onion
kjoabfljeghcinlpjhdbdfbcflapkccm
Risk Score
7.27
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy + privacy permissions allow full traffic interception and browser privacy-setting override by unverified Gmail dev.
- nativeMessaging with unrecognized publisher enables arbitrary native code execution on host machine.
- Extension abandoned 59 months ago (MV3 but >36mo stale); supply-chain takeover window is open.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Uninstall URL hijack set; developer identity is only a Gmail address with no verifiable business.
Evidence
- HIGH permissions: proxy+privacy+nativeMessaging manifest proxy can reroute all traffic; privacy alters browser settings; nativeMessaging executes native code — all with Gmail-only dev.
- nativeMessaging publisher_recognized=false crx Companion-app publisher not recognized; +3.0 Permissions per rule (15).
- Abandoned: 59 months since update store Last updated July 2021; >36mo threshold triggers +10.0 Maintenance and zombie risk.
- Privacy policy is generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (D clause).
- Uninstall URL hijack crx uninstall_url_hijack=true; +3.0 Webstore per rubric.
- Free-webmail developer, no business domain store tlintspr@gmail.com; no verified publisher, no business site; Reputation floor 7.5.
- install_perm_anomaly tail_attack_surface=true api 4,000 installs with high-tier permissions; +1.0 Webstore per rule (11).
- External hosts: api.github.com, check.torproject.org, github.com, webbrowsertools.com crx 4 distinct registrable domains; no CSP (MV3 so no +2.0 penalty); +1.5 Network for >3 domains.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled proxy; highest-impact permission.
- privacy high Can alter browser privacy settings (WebRTC, safe-browsing, etc.) globally.
- nativeMessaging high Executes arbitrary native code via companion app; publisher_recognized == false amplifies risk.
- storage low Local key-value storage; low standalone risk.
- notifications low Can display system notifications; low standalone risk.
Pillar Scores
Permissions9.00
Reputation7.50
Network3.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6</script><script>ITlQ(9383)</script> | 7.17 | High | block | 2026-08-05 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 7.26 | High | block | 2026-08-05 |
| bfgx5876%C0%BEz1%C0%BCz2a%90bcxhjl5876 | 7.59 | High | block | 2026-08-05 |
| v3.6&n998573=v940935 | 7.24 | High | block | 2026-08-05 |
| v3.6"><script>0TA9(9694)</script> | 6.37 | High | block | 2026-07-29 |
| v3.6"sTYLe='zzz:Expre/**/SSion(0TA9(9666))'bad=" | 7.34 | High | block | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 6.55 | High | block | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 6.48 | High | block | 2026-07-29 |
| bfgx8402%C0%BEz1%C0%BCz2a%90bcxhjl8402 | 7.17 | High | block | 2026-07-29 |
| <th:t="${dfb}#foreach | 7.43 | High | block | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >0TA9(9928)</ScRiPt> | 6.68 | High | block | 2026-07-29 |
| v3.6&n944495=v989481 | 7.47 | High | block | 2026-07-29 |
| v3.6 | 7.27 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
805e40bb2d96…
Force block
— not fired
Score recovered
no
Elapsed
25.7s