Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Jump VPN

lkoncffoonijombbicbdoekimimjdhif
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 123
Rating 4.9
Last updated 2026-06-10 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer namikkm13@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through neoncloak.space (RU/NL infra) with no accountability
  • Privacy policy is Google's generic policy — completely unscoped to this extension or its VPN data handling
  • Install hijack opens neoncloak.space on install; same domain hosts external JS — monetization/tracking vector
  • Developer is anonymous (gmail, no name, no verified publisher) with no business identity
  • Small install count + HIGH-tier permission (proxy) is a tail-attack-surface pattern

Evidence

  • install_url_hijack crx onInstalled opens https://neoncloak.space/ — same domain as external JS host, suggesting tracking/monetization.
  • proxy_permission manifest proxy declared — can redirect all browser HTTP/S traffic to arbitrary servers.
  • external_js_hosts crx JS contacts app.myxavpn.pro, neoncloak.space, t.me — 3 distinct domains, RU+NL geos.
  • privacy_policy_generic store Policy URL is Google's own account policy; fetched=true but scope_extension=false, data_collection=true, third_party_sharing=true → +10 privacy.
  • anonymous_developer store developer_name empty, gmail address, no verified publisher, no featured badge.
  • free_webmail_dev store namikkm13@gmail.com — free webmail, no business website, no dev identity.
  • small_install_high_perm api install_perm_anomaly: 123 installs with proxy (HIGH-tier) — tail-attack-surface pattern.
  • host_geo_diversity crx JS served from NL and RU — two countries; no CSP present (MV3 default only).

Permissions Breakdown

  • proxy high Full proxy control can redirect all browser traffic through attacker-controlled servers.

Pillar Scores

Permissions6.00
Reputation8.00
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:09
Listing SHA 1a57bb17b183…
Force block — not fired
Score recovered no
Elapsed