Hola VPN
kkkldlbbknfdbpalmknkdalimjeadpen
Risk Score
4.59
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission grants full traffic redirection capability; install redirect to turbotunnel.space (non-Hola domain) is a strong impersonation/hijack signal.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing without disclosure of what this extension collects.
- External JS hosts include app.myxavpn.pro and turbotunnel.space — unknown third-party infrastructure inconsistent with legitimate Hola VPN branding.
- No developer identity, no store listing metadata (name, installs, rating, update date) — unverifiable attribution, high counterfeit risk.
- Geo-diverse JS hosts across CA/NL/RU/US (4 countries) with Russian-language manifest description; pattern consistent with counterfeit/shadow VPN extension.
Evidence
- install_url_hijack crx onInstalled opens https://turbotunnel.space/ — unrelated to Hola brand; classic counterfeit extension redirect.
- proxy_permission manifest proxy declared; combined with turbotunnel.space infrastructure indicates traffic interception risk.
- external_hosts_suspicious crx JS contacts app.myxavpn.pro and turbotunnel.space — neither belongs to Hola VPN's known infrastructure.
- privacy_policy_generic_google store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true). Triggers +10.0 per v3.5(D).
- no_developer_identity store developer_name, developer_email all empty; no verified publisher; no featured badge.
- host_geo_diversity crx JS hosts span 4 countries (CA, NL, RU, US); RU-origin infrastructure with Russian-language description.
- manifest_name_brand_mismatch crx Manifest name 'Hola VPN' but install redirect and external hosts point to turbotunnel.space/myxavpn.pro — likely impersonation.
- csp_absent_mv3 manifest No content_security_policy declared; MV3 has strict default but absence noted alongside suspicious external hosts.
Permissions Breakdown
- proxy high Full proxy control can redirect all browser traffic through attacker-controlled infrastructure.
- https://cloudflare-dns.com/* medium Host permission for DoH resolver; expected for VPN/DNS but grants outbound access.
- https://dns.google/* medium Host permission for Google DoH; expected for VPN/DNS use case.
Pillar Scores
Permissions8.00
Reputation8.50
Network5.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:37
Listing SHA
763d113b3f5d…
Force block
— not fired
Score recovered
no
Elapsed
—