Jump VPN
lkoncffoonijombbicbdoekimimjdhif
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission routes all browser traffic through neoncloak.space (RU/NL infra) with no accountability
- Privacy policy is Google's generic policy — completely unscoped to this extension or its VPN data handling
- Install hijack opens neoncloak.space on install; same domain hosts external JS — monetization/tracking vector
- Developer is anonymous (gmail, no name, no verified publisher) with no business identity
- Small install count + HIGH-tier permission (proxy) is a tail-attack-surface pattern
Evidence
- install_url_hijack crx onInstalled opens https://neoncloak.space/ — same domain as external JS host, suggesting tracking/monetization.
- proxy_permission manifest proxy declared — can redirect all browser HTTP/S traffic to arbitrary servers.
- external_js_hosts crx JS contacts app.myxavpn.pro, neoncloak.space, t.me — 3 distinct domains, RU+NL geos.
- privacy_policy_generic store Policy URL is Google's own account policy; fetched=true but scope_extension=false, data_collection=true, third_party_sharing=true → +10 privacy.
- anonymous_developer store developer_name empty, gmail address, no verified publisher, no featured badge.
- free_webmail_dev store namikkm13@gmail.com — free webmail, no business website, no dev identity.
- small_install_high_perm api install_perm_anomaly: 123 installs with proxy (HIGH-tier) — tail-attack-surface pattern.
- host_geo_diversity crx JS served from NL and RU — two countries; no CSP present (MV3 default only).
Permissions Breakdown
- proxy high Full proxy control can redirect all browser traffic through attacker-controlled servers.
Pillar Scores
Permissions6.00
Reputation8.00
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:09
Listing SHA
1a57bb17b183…
Force block
— not fired
Score recovered
no
Elapsed
—