Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hoxx VPN Proxy

nbcojefnccbanplpoffopkoepjmhgdgh
Risk Score
6.05
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 700,000
Rating 4.6
Last updated 2025-01-20 (20 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@hoxx.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • proxy + <all_urls>: all browser traffic can be routed through Hoxx servers; compromise = full MITM.
  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — broad data sharing admitted without extension-specific scope.
  • management permission allows disabling/uninstalling other extensions — unusual for a VPN.
  • DOM-XSS innerHTML sinks in mainlink.js and popup.js combined with function_constructor in service-worker.

Evidence

  • proxy+<all_urls>+webRequest combo manifest proxy, webRequest, and <all_urls> together enable full traffic interception across all sites.
  • management permission manifest management declared — can enumerate and disable sibling extensions; atypical for VPN.
  • privacy policy scope mismatch crx Policy fetched (24788 chars); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • dom_sink_innerhtml_userctrl x2 + function_constructor crx Two innerHTML sinks (mainlink.js, popup.js) and new Function() in service-worker.js.
  • no developer_name store developer_name field is empty; reduces accountability signal.
  • 17 months since update store Last updated January 2025; 17 months maps to 3–6 month band for maintenance score.
  • is_featured_by_google=true store Google Featured badge provides partial trust signal; applied -2.0 reputation discount.
  • js_external_hosts includes github.com, mui.com, reactjs.org, redux.js.org crx 4 doc/CDN-style external hosts beyond hoxx.com account servers; doc sites unlikely to serve live JS.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers if compromised.
  • webRequest high Intercepts and inspects all network requests across all URLs.
  • management high Can enumerate, disable, or uninstall other extensions — elevated privilege.
  • <all_urls> high Host permission grants access to content on every site visited.
  • declarativeNetRequest medium Can block/redirect network requests; core to VPN/proxy function.
  • tabs medium Can read URL and title of all open tabs.
  • webRequestAuthProvider medium Can supply auth credentials for proxy authentication challenges.
  • notifications low Can display desktop notifications; low standalone risk.
  • alarms low Scheduled wake-ups; low risk in isolation.
  • storage low Local state storage; expected for VPN config persistence.

Pillar Scores

Permissions7.50
Reputation5.50
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Scoring History

sssiedncba9e190dp727562726963xsx 5.84 Medium block 2026-09-12
v3.6 6.05 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 7f7af4688632…
Force block 🚫 fired
Score recovered no
Elapsed 29.1s