Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ВПН для ЧатГПТ

phadahcflgdgodfbndbommabigemebhl
Risk Score
5.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 77
Rating 4.8
Last updated 2026-04-23 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer kameqoko032@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full traffic interception through zhuknet.online (RU-hosted, unknown operator)
  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
  • Install URL hijack opens zhuknet.online on install; developer identity unknown (free-webmail, no name)
  • Free-webmail developer (gmail), no developer name, no verified publisher — high impersonation risk
  • Small install base (77) with HIGH-tier permission is a tail-attack-surface anomaly

Evidence

  • proxy_permission manifest Extension declares 'proxy' — can route all browser traffic through attacker-controlled server zhuknet.online.
  • install_url_hijack crx onInstalled opens https://zhuknet.online — a third-party RU-hosted domain unknown to the user.
  • js_external_host crx External JS host: zhuknet.online (RU). Only 1 country in geo-diversity check.
  • generic_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store Developer email: kameqoko032@gmail.com (free webmail). No developer name, no verified publisher.
  • small_install_high_perm api install_perm_anomaly: 77 installs with HIGH-tier proxy permission — tail attack surface.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no accountability signals.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers, enabling MitM attacks.

Pillar Scores

Permissions7.00
Reputation8.50
Network2.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:10
Listing SHA c3bafd988af8…
Force block — not fired
Score recovered no
Elapsed