Apple VPN
kpmgcdgnpkbfajhgbmagkaccibnekbdm
Risk Score
6.61
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation: claims 'Apple VPN' but developer is a free-webmail Gmail account with no Apple affiliation.
- proxy permission routes all browser traffic through attacker-controlled endpoints (nimbusshield.space, app.myxavpn.pro).
- install_url_hijack opens nimbusshield.space on install — classic monetization/phishing redirect.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and third-party sharing.
- 8 installs with high-tier permission and no verified publisher — tail attack surface, likely probing for victims.
Evidence
- brand_impersonation store Title 'Apple VPN' claims Apple brand; developer is binoyihe32@gmail.com, confirmed_owner=false.
- install_url_hijack manifest onInstalled opens https://nimbusshield.space/ — third-party redirect on install.
- proxy_permission manifest proxy declared; routes all Chrome traffic through developer-controlled servers.
- external_js_hosts crx JS contacts app.myxavpn.pro, nimbusshield.space, t.me — 3 distinct domains across NL and RU.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_no_dev_name store developer_name empty, email binoyihe32@gmail.com — numbered-alias free-webmail pattern.
- small_install_high_perm api 8 installs with proxy (HIGH-tier) — install_perm_anomaly.small_install_high_perm=true.
- geo_diversity api JS hosts in NL and RU; RU-hosted proxy endpoint raises exfiltration concern.
Permissions Breakdown
- proxy high Full browser proxy control; can redirect all traffic through attacker-controlled servers.
Pillar Scores
Permissions7.00
Reputation9.00
Network5.00
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:59
Listing SHA
80de371f44ae…
Force block
— not fired
Score recovered
no
Elapsed
—