Hoxx VPN — скорость без лишних настроек
ommmigkmgbilkbggodbipeffbjdbcook
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- proxy permission on a 20-install extension from a free-webmail address with no developer name — trivial to intercept all browser traffic
- Install-URL hijack opens shieldtunnel.space (unrelated 3rd-party domain) immediately on install
- Privacy policy is Google's own generic policy — has no scope, does not describe this extension's data practices
- Free Gmail developer email, no developer name, no verified publisher — identity completely unverifiable
- JS contacts app.myxavpn.pro and shieldtunnel.space — unknown third-party hosts for a VPN with only 20 installs
Evidence
- proxy_permission manifest proxy declared — routes all browser traffic through extension-controlled server; HIGH-impact capability.
- install_url_hijack crx onInstalled opens https://shieldtunnel.space/ — third-party domain unrelated to a legitimate VPN provider.
- free_webmail_no_devname store developer_email=binoyihe32@gmail.com; developer_name empty; no verified publisher badge.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, covers Google not this extension.
- external_hosts_unknown crx JS contacts app.myxavpn.pro, shieldtunnel.space, t.me — non-vetted hosts for proxy/VPN traffic routing.
- tiny_install_high_perm store Only 20 installs with proxy (HIGH-tier) permission — classic tail-attack-surface / dropper pattern.
- geo_diversity api JS hosts span CA, NL, RU, US (4 countries) — includes Russia; elevated for a VPN with unknown operator.
- privacy_policy_admits_third_party_sharing api Classification: data_collection=true, third_party_sharing=true, scope_extension=false → v3.5(D) max score.
Permissions Breakdown
- proxy high Reroutes all browser traffic; a malicious actor can intercept/redirect every request.
- https://cloudflare-dns.com/* medium DNS-over-HTTPS host access; needed for VPN function but still a sensitive network endpoint.
- https://dns.google/* medium DNS-over-HTTPS host access; same rationale as cloudflare-dns.com.
Pillar Scores
Permissions7.00
Reputation8.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:20
Listing SHA
7db3ff1ba5e1…
Force block
— not fired
Score recovered
no
Elapsed
—