Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Какаду VPN

lkmnpfajdejfdbfjiaealafmogipbapk
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 96
Rating 5.0
Last updated 2026-06-08 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer oveyila408@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception; developer is anonymous Gmail account with no business identity
  • Privacy policy is Google's own generic policy — does not scope to this extension at all; scores maximum privacy risk
  • install_url_hijack opens horizonguard.space on install; JS contacts app.myxavpn.pro, horizonguard.space, t.me — unknown operators
  • No developer name, no verified publisher, free webmail only — anonymous high-capability extension
  • Small install count (96) with high-impact permission (proxy) matches tail-attack-surface anomaly

Evidence

  • proxy_permission manifest proxy declared — can redirect all browser traffic to arbitrary servers including horizonguard.space and app.myxavpn.pro
  • install_url_hijack crx onInstalled opens https://horizonguard.space/ — third-party domain not controlled by a verified developer
  • generic_privacy_policy store Privacy policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy score
  • anonymous_developer store developer_name empty, verified_publisher=false, email is Gmail; no business identity verifiable
  • js_external_hosts crx Extension contacts app.myxavpn.pro, horizonguard.space, t.me — 3 distinct external domains including Telegram
  • free_webmail_no_dev_name store oveyila408@gmail.com + empty developer_name triggers reputation floor of 7.5 per rubric
  • small_install_high_perm api 96 installs with proxy (HIGH-tier) permission; install_perm_anomaly.small_install_high_perm=true
  • host_geo_diversity api JS served from NL and RU — 2 countries; RU-hosted backend for a VPN warrants scrutiny

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; critical for a VPN but high-abuse potential.

Pillar Scores

Permissions2.00
Reputation8.00
Network2.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:57
Listing SHA 1887ab26ce4a…
Force block — not fired
Score recovered no
Elapsed