SpeedTop VPN – быстрый proxy с акцентом на скорость
oemjchklfcneghomigfkdeoleglhgocp
Risk Score
4.46
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission allows full traffic redirection through sverchvpn.space (RU-hosted, throwaway domain pattern)
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
- Developer uses free webmail (gmail) with no name, no business website, no verified publisher
- install_url_hijack detected — onInstalled opens a 3rd-party URL
- Small install base (580) with HIGH-tier permission (proxy) is a tail-attack-surface signal
Evidence
- proxy_permission manifest proxy declared; extension can silently reroute all Chrome traffic to any server.
- js_external_host crx Extension contacts sverchvpn.space (RU geo); unknown operator, not a recognised VPN provider.
- install_url_hijack crx install_url_hijack=true; onInstalled opens a 3rd-party page, typical monetisation/tracking behaviour.
- privacy_policy_generic store Policy URL is Google Account privacy policy — scope_extension=false, data_collection=true, 3rd_party_sharing=true.
- free_webmail_no_name store developer_email=ekugabezu505@gmail.com; developer_name empty; no business domain.
- small_install_high_perm api 580 installs + proxy (HIGH) flagged as small_install_high_perm by anomaly detector.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals.
Permissions Breakdown
- proxy high Full proxy control; can reroute all browser traffic through attacker-controlled infrastructure.
Pillar Scores
Permissions7.00
Reputation8.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:58
Listing SHA
11fec105b158…
Force block
— not fired
Score recovered
no
Elapsed
—