VPN Urban-proxy
lkpckmkognddjdhnoadepmgniifnfhek
Risk Score
4.37
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission allows full traffic interception/rerouting through skorostvpn.space (RU-hosted domain).
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (gmail) with no developer name, no verified publisher, no business website.
- Install URL hijack opens skorostvpn.space on installation — third-party redirect on an unknown Russian-hosted domain.
- Small install count (188) combined with high-tier proxy permission — tail attack surface concern.
Evidence
- proxy_permission manifest proxy declared — can silently redirect all browser traffic to skorostvpn.space (RU geo).
- install_url_hijack store install_url_hijack=true targeting https://skorostvpn.space/ on install.
- free_webmail_dev_no_name store Developer silviaferr79@gmail.com, no developer_name, no verified publisher, no business site.
- generic_privacy_policy store Privacy URL is Google account policy — scope_extension=false, admits data_collection and third_party_sharing.
- js_external_hosts crx Contacts cloudflare-dns.com, dns.google, skorostvpn.space — 3 distinct domains, one in RU geo.
- small_install_high_perm api install_perm_anomaly: 188 installs + proxy permission = tail attack surface.
- host_geo_diversity crx JS hosts span CA, RU, US — Russian-hosted VPN endpoint raises traffic interception risk.
- no_csp manifest csp_present=false on MV3; +2.0 network per v2 calibration rule (b).
Permissions Breakdown
- proxy high Can reroute all browser traffic through attacker-controlled servers; critical capability.
Pillar Scores
Permissions7.00
Reputation8.50
Network4.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:18
Listing SHA
49acc6f03b2b…
Force block
— not fired
Score recovered
no
Elapsed
—