Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

1Click VPN — Быстрое подключение в один клик

nlcohflbiiafbmndjmiginjjldfhhgni
Risk Score
4.18
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 14
Rating 5.0
Last updated 2026-07-31 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer utibubijih005@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Install URL hijack opens interstalsash.space (RU-hosted) on install — classic monetization/malware dropper pattern.
  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail dev (gmail), no developer name, no verified publisher — anonymous high-capability extension.
  • proxy permission allows complete redirection of all browser network traffic to attacker-controlled endpoints.
  • 14 installs + HIGH permission (proxy) = tail-attack-surface; supply-chain risk with near-zero public scrutiny.

Evidence

  • install_url_hijack crx onInstalled opens https://interstalsash.space — RU-hosted domain, no legitimate VPN provider association.
  • proxy_permission manifest proxy declared; can route all browser traffic through arbitrary servers with no host restriction.
  • anonymous_developer store developer_name empty, email utibubijah005@gmail.com (free webmail), not verified publisher, not featured.
  • privacy_policy_generic store Policy URL is Google account policy — scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_perm_anomaly api 14 installs + proxy (HIGH tier) = small_install_high_perm true; minimal public scrutiny on powerful capability.
  • js_external_hosts crx interstalsash.space is the sole external JS host; same domain as install hijack target — concentrated risk.
  • host_geo api All external hosts resolve to RU — single-country, non-CDN pattern for a VPN extension is anomalous.
  • no_csp manifest content_security_policy is null; MV3 provides some default protection but no explicit CSP declared.

Permissions Breakdown

  • proxy high Can intercept and redirect all network traffic — core VPN capability but extremely powerful.
  • storage low Stores extension settings locally; low standalone risk.

Pillar Scores

Permissions6.00
Reputation8.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:19
Listing SHA 76efae5bd726…
Force block — not fired
Score recovered no
Elapsed