Proton VPN
mlndifgbehammhhbecgfcpbcbmnfhooe
Risk Score
5.19
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation of Proton VPN: developer is anonymous gmail user with no affiliation to Proton AG.
- Install-URL hijack opens neoncloak.space on install — a third-party domain unrelated to Proton.
- JS external hosts include app.myxavpn.pro and neoncloak.space — suspicious non-Proton infrastructure.
- Privacy policy is Google's own policy (generic), not scoped to this extension; admits data collection and 3rd-party sharing.
- proxy permission allows full traffic interception/redirection; combined with unknown operator this is critical.
Evidence
- install_url_hijack crx onInstalled opens https://neoncloak.space/ — third-party domain with no relation to Proton AG.
- js_external_hosts crx Extension contacts app.myxavpn.pro, neoncloak.space, t.me — none are protonvpn.com or proton.me.
- developer_identity store Dev email imawocigi29@gmail.com (free webmail), no developer name, not a verified publisher.
- privacy_policy_generic store Policy URL is Google's own account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
- proxy_permission manifest proxy declared — allows full browser traffic redirection to attacker-controlled servers.
- brand_impersonation store Title 'Proton VPN' mimics registered Proton AG product; brand_mention.confirmed_owner=false.
- host_geo_diversity crx JS hosts span NL and RU — Russia-hosted infrastructure for a claimed privacy VPN is anomalous.
- no_csp manifest content_security_policy is null (csp_present=false) on MV3; +2.0 network penalty applied.
Permissions Breakdown
- proxy high Allows rerouting all browser traffic through an arbitrary proxy — critical for a VPN impostor.
Pillar Scores
Permissions2.00
Reputation8.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:19
Listing SHA
351490bed1c9…
Force block
— not fired
Score recovered
no
Elapsed
—