Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Дед VPN — защита и приватность онлайн

ojgndfedcnfkmohdcafiilpcenifhijd
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 17
Rating 4.8
Last updated 2026-06-09 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer egositburak@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through ironproxy.space — an unknown third-party server with RU/NL geo.
  • Privacy policy is Google's generic policy — not scoped to this extension; data_collection and third_party_sharing admitted.
  • Free-webmail dev (egositburak@gmail.com), no developer name, no verified publisher — identity unverifiable.
  • install_url_hijack opens ironproxy.space on install; only 17 installs with a HIGH-tier permission (tail attack surface).
  • JS external hosts include ironproxy.space and app.myxavpn.pro — unknown operators; no CSP to constrain them.

Evidence

  • proxy_permission manifest proxy declared — all browser traffic can be silently rerouted through ironproxy.space.
  • install_url_hijack store install_url_target=https://ironproxy.space/ — third-party site opened on every install.
  • js_external_hosts crx Extension contacts app.myxavpn.pro, ironproxy.space, t.me — 3 distinct external domains.
  • privacy_policy_generic store PP is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_no_devname store Developer email egositburak@gmail.com; developer_name empty; not verified publisher.
  • host_geo_diversity api JS hosts span NL and RU — two countries; RU-hosted proxy infra raises sovereignty risk.
  • small_install_high_perm api Only 17 installs with proxy (HIGH-tier) — tail attack surface anomaly flagged.
  • no_csp manifest content_security_policy is null; no CSP present on MV3 extension.

Permissions Breakdown

  • proxy high Proxy permission can reroute all browser traffic through attacker-controlled server.

Pillar Scores

Permissions6.00
Reputation7.50
Network4.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:04
Listing SHA eb587afd17e7…
Force block — not fired
Score recovered no
Elapsed