Chrome Web Store
1Versions
1Code reviewed

Do not install

Code review: critical

Our reviewer read this extension’s code and confirmed malicious behaviour. 3 security findings documented below. Do not install it. Remove it if you already have it.

What our analysis found

Mullvad VPN — Конфиденциальный VPN без ограничений is rated malicious by Extension Auditor. Our code review reported 3 findings (1 critical, 1 high, 1 medium), led by network interception. It comes from a publisher with 12 extensions and was last updated in August 2026.

Key findings

  • critical· network interception —All browser traffic except <local> is routed through a single hard-coded operator proxy,, which is unrelated to Mullvad, the brand the listing and UI claim. The operator therefore observes every hostname the user visits and can read and modify any plaintext HTTP request or response in transit. The CWS listing declares no data collection at all, so this routing of the user's entire browsing stream to a third party is wholly undisclosed.
  • high· phishing —The popup title and heading present the extension as "Mullvad VPN", an established commercial VPN brand, while the only network endpoint in the code (,:8) and the landing page opened on install (,:40) belong to an unrelated operator. Users are induced to hand their full browsing stream to that operator on the strength of a borrowed privacy brand. The privacy policy is a paste rather than a page on any domain the extension actually contacts.
  • medium· other —On install the extension force-opens an active tab at the operator's own domain, and:51-55 drives the glowing "Получить премиум бесплатно" ("Get premium for free") button to the same place. Neither destination relates to the impersonated brand, and the free-premium framing is a monetisation or credential-collection funnel driven from an extension the user installed believing it was Mullvad.

3-13 pins every non-local request to a hard-coded third-party proxy,, while the manifest,:6 and brand the extension as "Mullvad VPN" — a domain with no relation to Mullvad, and CWS data collection is declared as "none". The proxy link itself is TLS and HTTPS sites traverse it via CONNECT, so the operator cannot decrypt them, but it still receives every hostname the user visits and full access to plaintext HTTP; the install-time and "Получить премиум бесплатно" tabs both point at the same operator domain (:39-42,:51-55). Corroborating: the 38%-malicious permhash cluster and factory markers in-file (/* shape:D_router batch28 */, flag_b28_mullvad_vpn, ~15 unused layout-* classes, the b28 CSS block duplicated verbatim at:187-205 and 207-225). Discounted: the publisher's malicious count and our own malware label both trace to the same malext feed import, so they are circular, and chrome-stats cites a clipboard permission this extension does not request.

Mullvad VPN — Конфиденциальный VPN без ограничений

Mullvad VPN — Конфиденциальный VPN без ограничений

ID: nkhaoepgpgfmgfihbpeagjfjnchnfgpe

Supported Languages

🇷🇺Russian

Extension Info & Metadata

Status
Active
Version
1.1.4
Size
0.04 MB
Rating
5.0/5
Reviews
204
Users
372
Type
Extension
Updated
Aug 2, 2026
Category
Privacy & security
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
12extensions
7 no longer listed

Publisher Contextual Analysis

Author
afegoxiz432@gmail.comView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Extensions
12
Active
5
Obsolete
7
Listed
12
Unlisted
0
Users
615

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
proxy
Permission
Critical
This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
  • 1 critical
  • 1 high
  • 1 medium

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Короткий интерфейс: включил, проверил, продолжил работу.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
1.1.4
Latest
0.04 MBMalicious0
Showing 1 to 1 of 10 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.