ВПН для ЧатГПТ
phadahcflgdgodfbndbommabigemebhl
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission allows full traffic interception through zhuknet.online (RU-hosted, unknown operator)
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
- Install URL hijack opens zhuknet.online on install; developer identity unknown (free-webmail, no name)
- Free-webmail developer (gmail), no developer name, no verified publisher — high impersonation risk
- Small install base (77) with HIGH-tier permission is a tail-attack-surface anomaly
Evidence
- proxy_permission manifest Extension declares 'proxy' — can route all browser traffic through attacker-controlled server zhuknet.online.
- install_url_hijack crx onInstalled opens https://zhuknet.online — a third-party RU-hosted domain unknown to the user.
- js_external_host crx External JS host: zhuknet.online (RU). Only 1 country in geo-diversity check.
- generic_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity store Developer email: kameqoko032@gmail.com (free webmail). No developer name, no verified publisher.
- small_install_high_perm api install_perm_anomaly: 77 installs with HIGH-tier proxy permission — tail attack surface.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no accountability signals.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled servers, enabling MitM attacks.
Pillar Scores
Permissions7.00
Reputation8.50
Network2.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:10
Listing SHA
c3bafd988af8…
Force block
— not fired
Score recovered
no
Elapsed
—