Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Лови ВПН-Для серфа интернета

pmohoeododoachjkhdlifkmgoihmffij
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs
Rating
Last updated 2026-06-25 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer asdro1905@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission grants full traffic rerouting capability — all browser traffic can be intercepted via unverified server app.myxavpn.pro or silashield.space
  • Privacy policy is Google's own policy (myaccount.google.com), not scoped to this extension; admits data collection and third-party sharing
  • Developer is anonymous (no name, free Gmail, no business domain); no verified publisher badge
  • install_url_hijack=true: extension opens a third-party URL on install, typical of monetization shells
  • JS contacts silashield.space and t.me — unverified/suspicious external hosts alongside VPN infrastructure

Evidence

  • proxy_permission manifest proxy declared — can redirect all browser traffic to attacker-controlled infra (app.myxavpn.pro, silashield.space)
  • install_url_hijack crx install_url_hijack=true; onInstalled opens third-party URL — monetization/tracking pattern
  • generic_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to extension
  • anonymous_developer store No developer name, free Gmail asdro1905@gmail.com, no business domain, no verified publisher badge
  • suspicious_external_hosts crx JS contacts silashield.space (RU-hosted), t.me (Telegram), app.myxavpn.pro — unverifiable VPN backend
  • geo_diversity api JS hosts span CA, NL, RU, US — 4 countries; RU-hosted silashield.space is elevated-risk jurisdiction
  • free_webmail_dev store Developer email asdro1905@gmail.com is free webmail with no associated business website
  • no_csp manifest content_security_policy is null; MV3 strict default applies but no explicit hardening declared

Permissions Breakdown

  • proxy high Full proxy control — can reroute all browser traffic through any server, enabling MITM.
  • https://cloudflare-dns.com/* medium Host permission for DNS-over-HTTPS; legitimate for VPN but grants outbound DNS query access.
  • https://dns.google/* medium Host permission for Google DNS-over-HTTPS; same rationale as cloudflare-dns.com.

Pillar Scores

Permissions6.50
Reputation8.00
Network5.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 14:19
Listing SHA 7174f9003ba9…
Force block — not fired
Score recovered no
Elapsed