Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hola VPN

kkkldlbbknfdbpalmknkdalimjeadpen
Risk Score
4.59
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission grants full traffic redirection capability; install redirect to turbotunnel.space (non-Hola domain) is a strong impersonation/hijack signal.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing without disclosure of what this extension collects.
  • External JS hosts include app.myxavpn.pro and turbotunnel.space — unknown third-party infrastructure inconsistent with legitimate Hola VPN branding.
  • No developer identity, no store listing metadata (name, installs, rating, update date) — unverifiable attribution, high counterfeit risk.
  • Geo-diverse JS hosts across CA/NL/RU/US (4 countries) with Russian-language manifest description; pattern consistent with counterfeit/shadow VPN extension.

Evidence

  • install_url_hijack crx onInstalled opens https://turbotunnel.space/ — unrelated to Hola brand; classic counterfeit extension redirect.
  • proxy_permission manifest proxy declared; combined with turbotunnel.space infrastructure indicates traffic interception risk.
  • external_hosts_suspicious crx JS contacts app.myxavpn.pro and turbotunnel.space — neither belongs to Hola VPN's known infrastructure.
  • privacy_policy_generic_google store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true). Triggers +10.0 per v3.5(D).
  • no_developer_identity store developer_name, developer_email all empty; no verified publisher; no featured badge.
  • host_geo_diversity crx JS hosts span 4 countries (CA, NL, RU, US); RU-origin infrastructure with Russian-language description.
  • manifest_name_brand_mismatch crx Manifest name 'Hola VPN' but install redirect and external hosts point to turbotunnel.space/myxavpn.pro — likely impersonation.
  • csp_absent_mv3 manifest No content_security_policy declared; MV3 has strict default but absence noted alongside suspicious external hosts.

Permissions Breakdown

  • proxy high Full proxy control can redirect all browser traffic through attacker-controlled infrastructure.
  • https://cloudflare-dns.com/* medium Host permission for DoH resolver; expected for VPN/DNS but grants outbound access.
  • https://dns.google/* medium Host permission for Google DoH; expected for VPN/DNS use case.

Pillar Scores

Permissions8.00
Reputation8.50
Network5.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:37
Listing SHA 763d113b3f5d…
Force block — not fired
Score recovered no
Elapsed