Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Happ VPN — подключение в один клик

pgdehgjcmgedooamahelcjeoghbnhmek
Risk Score
5.46
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category VPN
Installs 70
Rating 5.0
Last updated 2026-07-20 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer sedatkilli87@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes all browser traffic through attacker-controlled infrastructure (bezopasnet.space, app.myxavpn.pro)
  • install_url_hijack opens bezopasnet.space on install — unsolicited third-party redirect
  • Privacy policy is Google's own policy, not scoped to this extension; data handling is undisclosed
  • Developer uses free Gmail, no name, no verified publisher — anonymous accountability
  • JS contacts RU/NL-hosted external domains; VPN proxy destination is unknown infrastructure

Evidence

  • proxy_permission manifest proxy declared — can silently redirect all HTTP/S traffic through any server the extension chooses.
  • install_url_hijack crx onInstalled opens https://bezopasnet.space/ — unsolicited third-party URL on install.
  • external_js_hosts crx Extension contacts app.myxavpn.pro, bezopasnet.space, t.me — unknown VPN backend and Telegram.
  • generic_privacy_policy store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true).
  • anonymous_developer store Developer name empty, free Gmail (sedatkilli87@gmail.com), no verified publisher, 70 installs.
  • geo_diversity api JS hosts in NL and RU — two countries; RU-hosted VPN backend raises jurisdictional risk.
  • small_install_high_perm api install_perm_anomaly: 70 installs with HIGH-tier proxy permission — tail attack surface.
  • csp_absent manifest No content_security_policy declared (MV3 default applies but no CSP field present).

Permissions Breakdown

  • proxy high Full proxy control allows routing all browser traffic through arbitrary servers, critical MITM risk.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:17
Listing SHA 5e345bf2ce5f…
Force block — not fired
Score recovered no
Elapsed