Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sokol Vpn

nhdjjcfgikohckacbdjcailhbnbbinjk
Risk Score
6.18
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 12
Rating 4.9
Last updated 2026-06-13 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer egositburak@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full browser traffic rerouting to maskirovka.space (Russia/NL hosted unknown operator)
  • Privacy policy is Google's generic policy — does not scope to this extension at all; admits data collection and 3rd-party sharing
  • Install URL hijack opens maskirovka.space on install — typical dropper/monetization shell behavior
  • Free-webmail developer (gmail), no developer name, no verified publisher — unaccountable operator
  • Only 12 installs with HIGH-tier permission (proxy) — tail attack surface; low-volume staging or targeted deployment

Evidence

  • install_url_hijack crx onInstalled opens https://maskirovka.space — third-party domain, Russia/NL geo, unknown operator.
  • js_external_hosts crx Extension contacts app.myxavpn.pro, maskirovka.space, t.me — 3 distinct external domains, NL+RU geo.
  • proxy_permission manifest proxy declared — can redirect all browser TCP connections to arbitrary servers.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_dev_name store Developer email egositburak@gmail.com, developer_name empty, not verified publisher.
  • install_perm_anomaly api 12 installs + proxy permission flagged as small_install_high_perm=true.
  • host_geo_diversity crx JS hosts span NL and RU — 2 countries; RU-hosted proxy backend is elevated-risk jurisdiction.
  • csp_absent manifest content_security_policy is null; no CSP on MV3 extension with external host contacts.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; maximum traffic interception risk.

Pillar Scores

Permissions7.50
Reputation8.00
Network5.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:16
Listing SHA 0d05277fb2a8…
Force block — not fired
Score recovered no
Elapsed