Chrome Web Store

ВПН для Gemini / VPN for Gemini

by [email protected] · 10.0K users · 4.0 rating
fc6eea62-00a6-57ad-9502-046fd8401882 | v3.0
56/ 100
MEDIUM risk
No change since v2.3
Threat verdict
Do not install

Confirmed member of a tracked malicious supply-chain campaign.

Analysis record

Analysed
6 days ago
Version
v3.0
Artifact
SHA256 2A5…894
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

61 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 16
font/Nunito/Nunito-ExtraBoldItalic.ttffont/Nunito/Nunito-Regular.ttffont/Nunito/Nunito-BoldItalic.ttf +13 more
-
LOWpostinstall crypto operations 3
js/bg.js_metadata/verified_contents.jsonjs/jquery.js
-
LOWpostinstall system command 7
tutorial/info.htmljs/bg.jstutorial/main.js +4 more
-
LOWpostinstall file manipulation 5
js/bg.jstutorial/main.jspopup/main.js +2 more
-
LOWpostinstall environment access 1
js/bg.js
-
LOWpostinstall obfuscation 3
js/bg.jspopup/main.jsjs/jquery.js
-
LOWpostinstall network communication 10
settings/night.cssjs/jquery.jssettings/total.html +7 more
-
LOWAlertStatementsShouldNotBeUsed 1
popup/main.js
-
LOWpostinstall file download 2
js/bg.js_metadata/verified_contents.json
-
LOWSQLInjection 1
js/jquery.js
-
LOWNoUseWeakRandom 3
js/bg.jspopup/main.jsjs/jquery.js
-
LOWLocalStorageShouldNotBeUsed 4
popup/checkout.jstutorial/main.jspopup/main.js +1 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

155 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

35
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

5
Network
155
IoC Indicators

YARA Rules Matched

12 rules(56 hits)
postinstall persistence mechanism postinstall crypto operations postinstall system command postinstall file manipulation postinstall environment access postinstall obfuscation postinstall network communication AlertStatementsShouldNotBeUsed postinstall file download SQLInjection NoUseWeakRandom LocalStorageShouldNotBeUsed

Requested Permissions

8 permissions
proxy

Control the browser's proxy settings

Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
webRequest

Intercept, modify, and block all network requests

High
browsingData
Medium
storage
Low
webRequestAuthProvider
Low
notifications
Low
offscreen
Low

Security Analysis Summary

Security Analysis Overview

ВПН для Gemini / VPN for Gemini is a Chrome Web Store extension published by [email protected]. Version 3.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 56.27/100 (MEDIUM risk) based on 216 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 160 finding(s)
  • Low: 56 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

ВПН для Gemini / VPN for Gemini is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 10K users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
56
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2.2
Mar 9, 2026
Risk range
56 to 57
Across analyzed versions
Latest analyzed version
3.0
Jul 6, 2026
Selected version
medium
Version
v3.0
2 months ago
Risk score
56
Findings
216
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Страна ограничивает доступ к полной версии ИИ? Не беда! 🚀 Наше VPN-расширение открывает 100% потенциал Gemini. Наш VPN дает вам билет в глобальную версию ИИ: - Используйте все экспериментальные функции первым. - Получайте ответы, не отфильтрованные локальными цензурами. - Общайтесь с ботом без ограничений. Обходите запреты одним кликом! Попробуй и убедись сам, на что способен твой ассистент. #Gemini #ИИ #VPN #ДоступБезГраниц #Технологии Gemini — семейство нейросетевых моделей искусственного интеллекта (ИИ), разработанных компанией Google DeepMind. Изначально модель называлась Google Bard, но в начале 2024 года её переименовали в Gemini в честь языковой модели, которая лежит в её основе.

Frequently Asked Questions