Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Radmin VPN — спокойный режим

pgcjglcfamomceaphhbmmhlbkbcmmhke
Risk Score
4.68
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs
Rating 5.0
Last updated 2026-07-23 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer sedatkilli87@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception/redirection to neoncloak.space and app.myxavpn.pro — unknown third-party VPN backends
  • install_url_hijack opens neoncloak.space on install — classic malicious onboarding redirect
  • Gmail dev address, no developer name, no verified publisher — unaccountable identity
  • Privacy policy is Google's own account policy — entirely unscoped to this extension; admits data collection and 3rd-party sharing
  • JS external hosts in NL and RU with no known-good reputation; extension impersonates legitimate Radmin VPN brand

Evidence

  • install_url_hijack crx onInstalled opens https://neoncloak.space/ — same domain as a JS external host; strong monetization/malware onboarding signal.
  • proxy_permission manifest proxy declared; routes all browser traffic through operator-chosen servers (app.myxavpn.pro, neoncloak.space).
  • js_external_hosts crx app.myxavpn.pro, neoncloak.space, t.me — two unknown VPN/proxy backends plus Telegram; geo: NL + RU.
  • privacy_policy_generic store Policy URL is Google Account privacy policy — scope_extension=false, data_collection=true, third_party_sharing=true. Triggers +10.0 privacy (D rule).
  • free_webmail_no_dev_name store developer_email=sedatkilli87@gmail.com, developer_name empty, verified_publisher=false — unverifiable identity.
  • brand_impersonation_risk store Title uses 'Radmin VPN' — a real product by Famatech — but developer is unrelated gmail user; brand_mention.is_impersonation=false per scanner, flagged manually.
  • no_csp manifest csp_present=false on MV3 extension; no content security policy declared.
  • host_geo_diversity api JS hosts span NL and RU (count=2); below geo-diversity threshold but RU backend for proxy is elevated risk.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers; extremely high capability risk.

Pillar Scores

Permissions7.00
Reputation8.50
Network5.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:11
Listing SHA ad7e236eb7a2…
Force block — not fired
Score recovered no
Elapsed