Огонь VPN
pmfbomilkmcfpnpgbdodmdbgapghehef
Risk Score
5.39
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy permission grants full network traffic redirection to unknown endpoints (app.myxavpn.pro, cloudmask.space)
- Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing
- Developer is anonymous (no name, free-webmail gmail), no verified publisher status
- install_url_hijack: onInstalled opens cloudmask.space — monetization/tracking redirect on install
- Small install base (290) with HIGH-tier permission is a classic tail-attack-surface fingerprint
Evidence
- proxy_permission manifest proxy declared — all browser traffic can be routed through attacker-controlled server.
- install_url_hijack store onInstalled opens https://cloudmask.space/ — monetization/tracking redirect pattern.
- external_js_hosts crx JS contacts app.myxavpn.pro, cloudmask.space, t.me — 3 distinct external domains including Telegram.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev_no_name store Developer namikkm13@gmail.com, no developer_name, no verified publisher, no business domain.
- small_install_high_perm api 290 installs with proxy (HIGH-tier) — install_perm_anomaly.small_install_high_perm=true.
- geo_diversity api JS hosted in NL and RU (2 countries); RU-hosted proxy backend raises jurisdiction risk.
- no_csp manifest content_security_policy is null — no CSP defined on MV3 extension.
Permissions Breakdown
- proxy high Controls all browser network traffic routing; complete traffic interception capability.
Pillar Scores
Permissions6.50
Reputation8.00
Network4.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 14:18
Listing SHA
5e0f32da8e44…
Force block
— not fired
Score recovered
no
Elapsed
—