Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

android VPN

pddhejgmgakilndagfaffgochjojogfp
Risk Score
4.32
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 91
Rating 4.6
Last updated 2026-06-13 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer aslikap21@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through echosecure.space, a single unverified Russian-hosted domain controlled by an anonymous Gmail developer.
  • Privacy policy is Google's own generic policy — not scoped to this extension; data collection/sharing terms are meaningless for this extension.
  • Developer is anonymous (no name, free Gmail, no business domain) with 91 installs and high-capability permission — classic tail-attack-surface.
  • install_url_hijack: onInstall opens echosecure.space, funneling users to the proxy operator's site immediately after install.
  • No CSP on an MV3 extension with proxy capability and an external JS host (echosecure.space) — no script-injection guardrails.

Evidence

  • proxy_permission manifest Permission 'proxy' declared — can intercept and redirect all browser HTTP/HTTPS traffic.
  • install_url_hijack crx install_url_target=https://echosecure.space/ — onInstalled opens operator site, monetization/tracking risk.
  • free_webmail_no_dev_name store Developer email aslikap21@gmail.com, no developer name — anonymous high-capability publisher.
  • generic_google_privacy_policy store Privacy URL is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
  • single_geo_russia api All JS external hosts resolve in RU — echosecure.space hosted in Russia.
  • small_install_high_perm api Only 91 installs with high-tier proxy permission — tail-attack-surface anomaly flagged.
  • no_csp manifest content_security_policy is null; no script-src restrictions despite external JS host.
  • external_js_host crx js_external_hosts=['echosecure.space'] — extension contacts unverified operator domain.

Permissions Breakdown

  • proxy high Can reroute all browser traffic through attacker-controlled servers; full network interception capability.
  • https://echosecure.space/* medium Narrow host permission to a single unverified domain hosting the proxy backend.

Pillar Scores

Permissions7.00
Reputation8.00
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:05
Listing SHA d76091accc57…
Force block — not fired
Score recovered no
Elapsed