Hoxx VPN Proxy
nbcojefnccbanplpoffopkoepjmhgdgh
Risk Score
6.05
Risk Level:
High
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
- proxy + <all_urls>: all browser traffic can be routed through Hoxx servers; compromise = full MITM.
- Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — broad data sharing admitted without extension-specific scope.
- management permission allows disabling/uninstalling other extensions — unusual for a VPN.
- DOM-XSS innerHTML sinks in mainlink.js and popup.js combined with function_constructor in service-worker.
Evidence
- proxy+<all_urls>+webRequest combo manifest proxy, webRequest, and <all_urls> together enable full traffic interception across all sites.
- management permission manifest management declared — can enumerate and disable sibling extensions; atypical for VPN.
- privacy policy scope mismatch crx Policy fetched (24788 chars); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- dom_sink_innerhtml_userctrl x2 + function_constructor crx Two innerHTML sinks (mainlink.js, popup.js) and new Function() in service-worker.js.
- no developer_name store developer_name field is empty; reduces accountability signal.
- 17 months since update store Last updated January 2025; 17 months maps to 3–6 month band for maintenance score.
- is_featured_by_google=true store Google Featured badge provides partial trust signal; applied -2.0 reputation discount.
- js_external_hosts includes github.com, mui.com, reactjs.org, redux.js.org crx 4 doc/CDN-style external hosts beyond hoxx.com account servers; doc sites unlikely to serve live JS.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled servers if compromised.
- webRequest high Intercepts and inspects all network requests across all URLs.
- management high Can enumerate, disable, or uninstall other extensions — elevated privilege.
- <all_urls> high Host permission grants access to content on every site visited.
- declarativeNetRequest medium Can block/redirect network requests; core to VPN/proxy function.
- tabs medium Can read URL and title of all open tabs.
- webRequestAuthProvider medium Can supply auth credentials for proxy authentication challenges.
- notifications low Can display desktop notifications; low standalone risk.
- alarms low Scheduled wake-ups; low risk in isolation.
- storage low Local state storage; expected for VPN config persistence.
Pillar Scores
Permissions7.50
Reputation5.50
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Scoring History
| sssiedncba9e190dp727562726963xsx | 5.84 | Medium | block | 2026-09-12 |
| v3.6 | 6.05 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
7f7af4688632…
Force block
🚫 fired
Score recovered
no
Elapsed
29.1s