Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Матрёшка VPN

npminpkniohlengkpngnepjllnfapelj
Risk Score
4.25
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 65
Rating 4.8
Last updated 2026-04-23 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer sedatkilli87@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through gusentun.space, a dev-controlled domain with no business transparency
  • install URL hijack on onInstalled opens third-party site gusentun.space — classic monetization/tracking shell pattern
  • Privacy policy is Google's generic policy — not scoped to this extension; data_collection=true and third_party_sharing=true admitted
  • Free-webmail developer (gmail), no developer name, no verified publisher — unaccountable identity
  • 65 installs + HIGH permission (proxy) flagged as tail-attack-surface anomaly; very low visibility for such a powerful capability

Evidence

  • install_url_hijack crx onInstalled opens https://gusentun.space — third-party domain, monetization/tracking indicator.
  • proxy_permission manifest proxy declared; all browser traffic can be tunneled through attacker-chosen server.
  • js_external_host crx gusentun.space is sole external JS host — same domain as install hijack target, single-operator control.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_devname store Developer email sedatkilli87@gmail.com, no developer name, no verified publisher badge.
  • install_perm_anomaly api 65 installs with HIGH-tier permission (proxy); small_install_high_perm=true.
  • csp_absent_mv3 manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening.
  • host_geo api All JS hosted in RU (Russia); single country, aligns with stated bypass-of-Russian-blocks use-case but unverifiable.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled server; fundamental VPN/proxy capability but high abuse potential.

Pillar Scores

Permissions5.50
Reputation8.50
Network3.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:18
Listing SHA c1865e6a933e…
Force block — not fired
Score recovered no
Elapsed