Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Дядя Ваня VPN

lbbnpjbbepimfemibkhddfklekaipjli
Risk Score
5.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 9
Rating 5.0
Last updated 2026-06-07 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer aslikap21@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception via horizonguard.space and app.myxavpn.pro (NL/RU hosted)
  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection & 3rd-party sharing
  • install_url_hijack redirects to horizonguard.space on install — unsolicited navigation to unverified domain
  • Free-webmail dev (gmail), no developer name, no verified publisher — identity completely unverifiable
  • Only 9 installs with HIGH-tier permission (proxy) — classic tail-attack-surface profile

Evidence

  • proxy_permission manifest proxy declared — can silently redirect all browser traffic to attacker-controlled endpoints.
  • install_url_hijack store onInstalled opens https://horizonguard.space/ — unsolicited redirect to unverified third-party domain.
  • js_external_hosts crx Extension contacts app.myxavpn.pro, horizonguard.space (RU/NL), and t.me — unverified external infra.
  • privacy_policy_generic store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store dev email aslikap21@gmail.com (free webmail), no developer name, no verified publisher badge.
  • small_install_high_perm api Only 9 installs with proxy (HIGH) permission — install_perm_anomaly.small_install_high_perm=true.
  • geo_diversity crx JS hosts span NL and RU — two countries; moderate geo spread for a VPN with no verified operator.
  • csp_absent manifest content_security_policy is null; no CSP protection despite MV3 (MV3 has strict default but no explicit extension CSP).

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; highest-impact VPN permission.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:34
Listing SHA d5ad67f552d0…
Force block — not fired
Score recovered no
Elapsed