1Click VPN — Быстрое подключение в один клик
nlcohflbiiafbmndjmiginjjldfhhgni
Risk Score
4.18
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Install URL hijack opens interstalsash.space (RU-hosted) on install — classic monetization/malware dropper pattern.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail dev (gmail), no developer name, no verified publisher — anonymous high-capability extension.
- proxy permission allows complete redirection of all browser network traffic to attacker-controlled endpoints.
- 14 installs + HIGH permission (proxy) = tail-attack-surface; supply-chain risk with near-zero public scrutiny.
Evidence
- install_url_hijack crx onInstalled opens https://interstalsash.space — RU-hosted domain, no legitimate VPN provider association.
- proxy_permission manifest proxy declared; can route all browser traffic through arbitrary servers with no host restriction.
- anonymous_developer store developer_name empty, email utibubijah005@gmail.com (free webmail), not verified publisher, not featured.
- privacy_policy_generic store Policy URL is Google account policy — scope_extension=false, data_collection=true, third_party_sharing=true.
- install_perm_anomaly api 14 installs + proxy (HIGH tier) = small_install_high_perm true; minimal public scrutiny on powerful capability.
- js_external_hosts crx interstalsash.space is the sole external JS host; same domain as install hijack target — concentrated risk.
- host_geo api All external hosts resolve to RU — single-country, non-CDN pattern for a VPN extension is anomalous.
- no_csp manifest content_security_policy is null; MV3 provides some default protection but no explicit CSP declared.
Permissions Breakdown
- proxy high Can intercept and redirect all network traffic — core VPN capability but extremely powerful.
- storage low Stores extension settings locally; low standalone risk.
Pillar Scores
Permissions6.00
Reputation8.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:19
Listing SHA
76efae5bd726…
Force block
— not fired
Score recovered
no
Elapsed
—