Is Открывашка safe?

High risk

Открывашка is high risk. This extension proxies all traffic via a PAC script from an operator-controlled GCS file. The PAC URL comes from a second GCS registry JSON, updatable anytime and refreshed every 6 hours, redirecting traffic to any proxy without an update.…

speedboostownerv1.7.3Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

All browser traffic routed via PAC script from operator-controlled cloud storage

This extension proxies all traffic via a PAC script from an operator-controlled GCS file.

The PAC URL comes from a second GCS registry JSON, updatable anytime and refreshed every 6 hours, redirecting traffic to any proxy without an update.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open your browser with the extension installed.

No user interaction is needed, the PAC script fetch fires automatically on service worker startup.

The extension did this

The extension fetches routing rules from an operator-controlled GCS file and applies them as a system-wide proxy for all browser traffic.

The operator can change the routing rules at any time by updating the GCS files, without releasing a new extension version.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://storage.googleapis.com/otkryvashka/pca-scripts-registry-google.json
Returns a JSON object with keys 'free', 'premium', 'freeLite', 'premiumLite', each containing the URL of the PAC script to apply for that tier.
03EvidenceCODE COMPARE
The code that does this

PAC script fetch and proxy activation

What it actually does
// service_worker.js line ~1991 — registry fetch
const registryPath = isDevMode
 ? 'otkryvashka/pca-scripts-registry-google-test.json'
 : 'otkryvashka/pca-scripts-registry-google.json';
const registryUrl = configsBaseUrl === 'https://storage.yandexcloud.net/vpnn-web-configs/'
 ? new URL('otkryvashka/pca-scripts-registry-yandex.json', 'https://storage.yandexcloud.net/vpnn-web-configs/')
 : new URL(registryPath, 'https://storage.googleapis.com/');
const registry = await httpClient.get(registryUrl.toString).json;

// service_worker.js line ~4463-4491 — PAC script activation
const proxyConfig = {
 mode: 'pac_script',
 pacScript: { data: fetchedPacScriptString }
};
await chrome.proxy.settings.set({ value: proxyConfig, scope: 'regular' });

// service_worker.js line ~4755 — 6-hour refresh alarm
chrome.alarms.create('UpdatePacData', { periodInMinutes: 360 });
04EvidenceTEMPORAL PATTERN
When this fires
On every browser startup

PAC script fetched from operator-controlled GCS on every service worker startup and refreshed via a 6-hour alarm (UpdatePacData). Any change to the GCS registry or PAC file takes effect within 6 hours on all active installs.

05EvidenceTHIRD PARTY LIST
Operator-controlled infrastructure for PAC script delivery
  • storage.googleapis.com

    Primary GCS bucket hosting the PAC registry (otkryvashka/pca-scripts-registry-google.json) and PAC files. Operator has write access; changes reach all installs within 6 hours.

  • storage.yandexcloud.net

    Yandex Cloud Storage fallback bucket (vpnn-web-configs bucket). Used as the PAC registry source when configsBaseUrl points to Yandex. Same operator-controlled content.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Persistent browser fingerprint sent to Google Analytics on every session

Dynamic analysis captured 15 POSTs to Google Analytics per session, each carrying a permanent client_id from first launch, present in every event.

This lets Analytics build a per-install activity log, undisclosed in the Store listing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension and open your browser.

No interaction is needed, the service worker fires automatically on startup.

The extension did this

The extension POSTs your permanent client_id to Google Analytics.

The same identifier is used for every future event, creating a durable cross-session activity log.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.google-analytics.com/mp/collect?measurement_id=G-XCPV2XK66M&api_secret=<redacted>
HTTP 204 No Content (GA accepted the event)
Headers
Content-Typeapplication/json
Body
{
  "client_id": "25f060d7-de5f-427d-b184-44147d043970",
  "events": [
    {
      "name": "user_action",
      "params": {
        "action": "user_created",
        "session_id": "1780870378576",
        "engagement_time_msec": 100
      }
    }
  ]
}
03EvidenceFIELD TABLE
Fields sent in every Google Analytics event
FieldValueWhy it matters
Permanent browser ID
25f060d7-de5f-427d-b184-44147d043970A UUID generated on first launch that never changes. It lets Google Analytics link every future event to your specific browser installation.
Session ID
1780870378576A timestamp-derived ID that groups events within a 30-minute window. Resets if more than 30 minutes pass between events.
Event name and action
user_action / action: autostartWhat you were doing when the event fired, e.g. installing the extension, starting the browser, or hitting an error.
04EvidenceCODE COMPARE
The code that does this

Service worker: getOrCreateClientId and sendEvent

What it actually does
// service_worker.js line 2536-2596
getOrCreateClientId {
 const { clientId } = await chrome.storage.local.get('ClientId');
 if (typeof clientId === 'string') return clientId;
 const uuid = self.crypto.randomUUID;
 await chrome.storage.local.set({ ClientId: uuid });
 return uuid;
}

sendEvent(event) {
 const [clientId, sessionId] = await Promise.all([
 this.getOrCreateClientId,
 this.getOrCreateSessionId
 ]);
 const payload = {
 client_id: clientId,
 events: [{ name: event.name, params: { session_id: sessionId, engagement_time_msec: 100, ...event.params } }]
 };
 await fetch(
 'https://www.google-analytics.com/mp/collect?measurement_id=G-XCPV2XK66M&api_secret=<redacted>',
 { method: 'POST', body: JSON.stringify(payload) }
 );
}
05EvidenceTHIRD PARTY LIST
Destination receiving the tracking data
  • www.google-analytics.com

    Google Analytics Measurement Protocol endpoint. Receives the permanent client_id, session_id, and event metadata, processed by Google LLC under its analytics terms of service.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Account auto-created on install; device ID and IP sent to remote API

A POST fires on install, creating an account on the operator's server with your device ID and public IP before interaction begins.

The server address comes from a GCS JSON file, so the operator can redirect it anytime, unannounced.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension.

No further action is needed, the registration call fires during the install event handler.

The extension did this

The extension creates an account on the operator's server using your device ID and public IP address.

The registration target is resolved from a remote config file, so it can be changed by the operator without an extension update.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://opener.website/premium/api/v1/uboost-premium/create-new-user
Returns {userId: "<uuid>"} which is persisted to chrome.storage.local and a cookie on the apiBaseUrl domain.
Headers
Content-Typeapplication/json
Body
{
  "deviceId": "c4815874-fd71-4c08-9ab1-082a3d4aed6f",
  "deviceIp": "203.0.113.47"
}
03EvidenceFIELD TABLE
Data sent in the account creation request
FieldValueWhy it matters
Device identifier
c4815874-fd71-4c08-9ab1-082a3d4aed6fA UUID generated by the extension that uniquely identifies your device across sessions. Sent on every subscription check after registration.
Public IP address
203.0.113.47Your device's public IP address at the time of install. This reveals your approximate location and network provider.
04EvidenceCODE COMPARE
The code that does this

Install handler: remote config fetch then createNewUser call

What it actually does
// service_worker.js line ~4924-4937 (runtimeOnInstalledListener)
if (event.reason === 'install') {
 await initDeviceId;
 const { userId } = await chrome.storage.local.get('UserId');
 const { userId: cookieUserId } = await loadUserIdFromCookie(cookieDomain);
 if (!userId && !cookieUserId) {
 // Fires createNewUser — no consent prompt
 await createNewUser(ModeEnum.New, { isGuestMode: true, isSaleActive: false, isTrial: false });
 }
}

// service_worker.js line ~1356-1361 (createNewUser endpoint)
const CREATE_NEW_USER_PATH = 'premium/api/v1/uboost-premium/create-new-user';
// apiBaseUrl comes from otkryvashka.json fetched from GCS:
// https://storage.googleapis.com/otkryvashka/otkryvashka.json
05EvidenceTHIRD PARTY LIST
Servers receiving registration and subscription data
  • storage.googleapis.com

    Operator-controlled GCS bucket. Hosts otkryvashka.json, supplying the current apiBaseUrl; the operator can edit it to redirect registration calls to any server.

  • opener.website

    Primary API server (apiBaseUrl resolved at runtime). Receives device ID, public IP on install; receives userId + deviceId + deviceIp on each subsequent subscription check.

What it can do

Permissions this extension asks for, as declared in version 1.7.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on youtube.com

    https://*.youtube.com/*

  • Read and change your data on youtu.be

    https://*.youtu.be/*

  • Read and change your data on googlevideo.com

    https://*.googlevideo.com/*

  • Read and change your data on play.google.com

    https://*.play.google.com/*

  • Read and change your data on ytimg.com

    https://*.ytimg.com/*

  • Read and change your data on witch.tv

    https://*.witch.tv/*

  • Read and change your data on staticfiles.cukubst.top

    https://staticfiles.cukubst.top/*

  • Read and change your data on uboost.space

    https://uboost.space/*

  • Read and change your data on ubst.space

    https://ubst.space/*

  • Read and change your data on sentry-ws-1.vpnn.space

    *://sentry-ws-1.vpnn.space/*

  • Read and change your data on vpnn.loan

    *://*.vpnn.loan/*

  • Read and change your data on yandexcloud.net

    *://*.yandexcloud.net/*

  • Read and change your data on every site you visit

    <all_urls>

  • Route all of your browsing through a server of its choosing

    proxy

  • Store data in your browser

    storage

  • Watch every request your browser makes

    webRequest

  • Act on the current tab, but only after you click the extension

    activeTab

  • See the address and title of every tab you have open

    tabs

  • Schedule its own background tasks

    alarms

  • See, disable and uninstall your other extensions, including your security ones

    management

  • Read and change cookies, including the ones that keep you signed in

    cookies

webRequestAuthProvider
Updated 30 September 2026khpkadmigccakicajloljbckokgnknkp