Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AdGuard VPN

miiolehfoldajjpfjcnajmalaojhjaoa
Risk Score
6.27
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 10
Rating 5.0
Last updated 2026-06-15 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ekugabezu505@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation of AdGuard VPN by free-webmail gmail dev with no developer name — classic fraud pattern.
  • install_url_hijack opens securepulse.space on install; JS also loads app.myxavpn.pro and t.me — unknown third-party infra.
  • proxy permission gives full traffic interception capability to an unverified actor with 10 installs.
  • Privacy policy is Google's own policy — not scoped to this extension; data_collection and third_party_sharing both true.
  • JS external hosts span NL and RU; securepulse.space is non-brand domain inconsistent with AdGuard identity.

Evidence

  • brand_impersonation store Title 'AdGuard VPN' but developer is ekugabezu505@gmail.com with no verified publisher badge and no dev name.
  • install_url_hijack crx onInstalled opens https://securepulse.space — unrelated third-party domain, monetization/phishing risk.
  • js_external_hosts crx Extension contacts app.myxavpn.pro, securepulse.space, t.me — none are adguard.com infrastructure.
  • proxy_permission manifest proxy declared; unverified gmail dev can route all browser traffic through arbitrary server.
  • privacy_policy_generic store PP URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_dev_name store Developer email ekugabezu505@gmail.com, developer_name empty, no verified publisher.
  • install_perm_anomaly api 10 installs + proxy (HIGH permission) — small_install_high_perm=true; tail attack surface.
  • host_geo_diversity crx JS hosts span NL and RU (country_count=2); RU-hosted infra under fake AdGuard brand is elevated risk.

Permissions Breakdown

  • proxy high Routes all browser traffic through attacker-controlled server; maximum network intercept capability.

Pillar Scores

Permissions7.00
Reputation9.50
Network4.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:04
Listing SHA 7756bbb50f6a…
Force block — not fired
Score recovered no
Elapsed