VPN Proxy Master: Change IP for Chrome
lnfdmdhmfbimhhpaeocncdlhiodoblbd
Risk Score
6.24
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- proxy + webRequest + *://*/* grants full traffic interception and rerouting capability over all browser connections
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — triggers +10.0 privacy score
- Uninstall URL hijack detected — extension registers a third-party URL on uninstall
- CSP allows doubleclick.net and GTM alongside proxy capability — ad-tech monetization signals in a VPN extension
- Two unknown redirect domains (301.flashpull.com, 301.fastwalk.net) granted explicit host permissions with unclear purpose
Evidence
- proxy+webRequest+*://*/* manifest proxy, webRequest, webRequestAuthProvider combined with *://*/* host perm — full traffic MITM surface.
- privacy_policy_scope_mismatch crx Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — D clause triggers +10.
- uninstall_url_hijack crx uninstall_url_hijack=true; target unknown. Webstore +3.0 applied.
- monetization_hits crx doubleclick.net, google-analytics.com, googletagmanager.com in CSP/host_permissions for a VPN extension.
- unknown_redirect_domains manifest 301.flashpull.com and 301.fastwalk.net granted explicit host permissions; purpose undisclosed.
- function_constructor crx new Function() constructor found in options.js and popup.js — code quality risk +2.5.
- verified_publisher store verified_publisher=true; monetization_hits non-empty → v3.5 invariant 0c caps discount at -1.0.
- no_developer_name store developer_name is empty string; no 'Offered by' display name visible in listing data.
Permissions Breakdown
- proxy high Full proxy control — can route all browser traffic through attacker-controlled servers.
- webRequest high Intercepts all browser requests; combined with proxy enables full MITM capability.
- webRequestAuthProvider high Can supply credentials for auth challenges — extends MITM surface.
- unlimitedStorage low Allows unlimited local storage; low standalone risk.
- notifications low Can push notifications; low risk in isolation.
- storage low Standard local storage; low risk.
- *://*/* high Broad host permission covers all URLs; combined with proxy/webRequest is critical surface.
- https://vpnproxymaster.com/* low Dev-controlled domain; expected for VPN service.
- https://www.google.com/* low Google connectivity check; common but expands host surface.
- https://301.flashpull.com/* medium Unknown third-party redirect domain; purpose unclear.
- http://301.fastwalk.net/* medium Unknown third-party redirect domain over plain HTTP; purpose unclear.
- https://www.google-analytics.com/* low Analytics host permission; telemetry.
Pillar Scores
Permissions7.50
Reputation3.50
Network5.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
dd4ff8b8a068…
Force block
— not fired
Score recovered
no
Elapsed
28.5s