Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN Proxy Master: Change IP for Chrome

lnfdmdhmfbimhhpaeocncdlhiodoblbd
Risk Score
6.24
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 100,000
Rating 3.9
Last updated 2025-07-05 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer vpnproxymaster-support@inconnecting.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy + webRequest + *://*/* grants full traffic interception and rerouting capability over all browser connections
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — triggers +10.0 privacy score
  • Uninstall URL hijack detected — extension registers a third-party URL on uninstall
  • CSP allows doubleclick.net and GTM alongside proxy capability — ad-tech monetization signals in a VPN extension
  • Two unknown redirect domains (301.flashpull.com, 301.fastwalk.net) granted explicit host permissions with unclear purpose

Evidence

  • proxy+webRequest+*://*/* manifest proxy, webRequest, webRequestAuthProvider combined with *://*/* host perm — full traffic MITM surface.
  • privacy_policy_scope_mismatch crx Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — D clause triggers +10.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target unknown. Webstore +3.0 applied.
  • monetization_hits crx doubleclick.net, google-analytics.com, googletagmanager.com in CSP/host_permissions for a VPN extension.
  • unknown_redirect_domains manifest 301.flashpull.com and 301.fastwalk.net granted explicit host permissions; purpose undisclosed.
  • function_constructor crx new Function() constructor found in options.js and popup.js — code quality risk +2.5.
  • verified_publisher store verified_publisher=true; monetization_hits non-empty → v3.5 invariant 0c caps discount at -1.0.
  • no_developer_name store developer_name is empty string; no 'Offered by' display name visible in listing data.

Permissions Breakdown

  • proxy high Full proxy control — can route all browser traffic through attacker-controlled servers.
  • webRequest high Intercepts all browser requests; combined with proxy enables full MITM capability.
  • webRequestAuthProvider high Can supply credentials for auth challenges — extends MITM surface.
  • unlimitedStorage low Allows unlimited local storage; low standalone risk.
  • notifications low Can push notifications; low risk in isolation.
  • storage low Standard local storage; low risk.
  • *://*/* high Broad host permission covers all URLs; combined with proxy/webRequest is critical surface.
  • https://vpnproxymaster.com/* low Dev-controlled domain; expected for VPN service.
  • https://www.google.com/* low Google connectivity check; common but expands host surface.
  • https://301.flashpull.com/* medium Unknown third-party redirect domain; purpose unclear.
  • http://301.fastwalk.net/* medium Unknown third-party redirect domain over plain HTTP; purpose unclear.
  • https://www.google-analytics.com/* low Analytics host permission; telemetry.

Pillar Scores

Permissions7.50
Reputation3.50
Network5.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA dd4ff8b8a068…
Force block — not fired
Score recovered no
Elapsed 28.5s