Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hiddify VPN

lnmkicmjchoonmpmfpkjlbiejkepdjmh
Risk Score
5.88
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 245
Rating 5.0
Last updated 2026-06-20 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer oveyila408@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full rerouting of all browser traffic through unverified server (turbotunnel.space / app.myxavpn.pro).
  • install_url_hijack opens turbotunnel.space on install — unknown third-party site, strong monetization/tracking signal.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Free-webmail developer (gmail), no developer name, 245 installs — unverifiable identity controlling full proxy capability.
  • JS external hosts include t.me (Telegram) and app.myxavpn.pro alongside declared DNS hosts — undeclared exfil surface.

Evidence

  • proxy_permission manifest proxy declared; allows extension to redirect all browser traffic to turbotunnel.space or app.myxavpn.pro.
  • install_url_hijack crx onInstalled opens https://turbotunnel.space/ — undisclosed third-party site, monetization/tracking risk.
  • free_webmail_no_devname store Developer is oveyila408@gmail.com with no developer name listed; unverifiable identity.
  • generic_privacy_policy api Policy is Google account privacy page; scope_extension=false, admits data_collection and third_party_sharing.
  • undeclared_js_hosts crx JS contacts app.myxavpn.pro, t.me, turbotunnel.space beyond declared host_permissions.
  • geo_diversity api JS hosts span 4 countries: CA, NL, RU, US — elevated for a VPN with 245 installs.
  • tail_attack_surface api install_perm_anomaly: small_install_high_perm=true (245 installs, proxy permission).
  • no_csp manifest content_security_policy is null; MV3 provides some default protection but no explicit CSP declared.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled server; critical capability for VPN-style exfil.
  • https://cloudflare-dns.com/* medium DNS-over-HTTPS host; legitimate for VPN but extends network reach.
  • https://dns.google/* medium DNS-over-HTTPS host; legitimate for VPN but extends network reach.

Pillar Scores

Permissions6.00
Reputation8.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:10
Listing SHA 6913deb7f83d…
Force block — not fired
Score recovered no
Elapsed