Is Открывашка safe?
Открывашка is high risk. This extension proxies all traffic via a PAC script from an operator-controlled GCS file. The PAC URL comes from a second GCS registry JSON, updatable anytime and refreshed every 6 hours, redirecting traffic to any proxy without an update.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
All browser traffic routed via PAC script from operator-controlled cloud storage
This extension proxies all traffic via a PAC script from an operator-controlled GCS file.
The PAC URL comes from a second GCS registry JSON, updatable anytime and refreshed every 6 hours, redirecting traffic to any proxy without an update.
You open your browser with the extension installed.
No user interaction is needed, the PAC script fetch fires automatically on service worker startup.
The extension fetches routing rules from an operator-controlled GCS file and applies them as a system-wide proxy for all browser traffic.
The operator can change the routing rules at any time by updating the GCS files, without releasing a new extension version.
PAC script fetch and proxy activation
// service_worker.js line ~1991 — registry fetch
const registryPath = isDevMode
? 'otkryvashka/pca-scripts-registry-google-test.json'
: 'otkryvashka/pca-scripts-registry-google.json';
const registryUrl = configsBaseUrl === 'https://storage.yandexcloud.net/vpnn-web-configs/'
? new URL('otkryvashka/pca-scripts-registry-yandex.json', 'https://storage.yandexcloud.net/vpnn-web-configs/')
: new URL(registryPath, 'https://storage.googleapis.com/');
const registry = await httpClient.get(registryUrl.toString).json;
// service_worker.js line ~4463-4491 — PAC script activation
const proxyConfig = {
mode: 'pac_script',
pacScript: { data: fetchedPacScriptString }
};
await chrome.proxy.settings.set({ value: proxyConfig, scope: 'regular' });
// service_worker.js line ~4755 — 6-hour refresh alarm
chrome.alarms.create('UpdatePacData', { periodInMinutes: 360 });PAC script fetched from operator-controlled GCS on every service worker startup and refreshed via a 6-hour alarm (UpdatePacData). Any change to the GCS registry or PAC file takes effect within 6 hours on all active installs.
- storage.googleapis.com
Primary GCS bucket hosting the PAC registry (otkryvashka/pca-scripts-registry-google.json) and PAC files. Operator has write access; changes reach all installs within 6 hours.
- storage.yandexcloud.net
Yandex Cloud Storage fallback bucket (vpnn-web-configs bucket). Used as the PAC registry source when configsBaseUrl points to Yandex. Same operator-controlled content.
Persistent browser fingerprint sent to Google Analytics on every session
Dynamic analysis captured 15 POSTs to Google Analytics per session, each carrying a permanent client_id from first launch, present in every event.
This lets Analytics build a per-install activity log, undisclosed in the Store listing.
You install the extension and open your browser.
No interaction is needed, the service worker fires automatically on startup.
The extension POSTs your permanent client_id to Google Analytics.
The same identifier is used for every future event, creating a durable cross-session activity log.
| Content-Type | application/json |
{
"client_id": "25f060d7-de5f-427d-b184-44147d043970",
"events": [
{
"name": "user_action",
"params": {
"action": "user_created",
"session_id": "1780870378576",
"engagement_time_msec": 100
}
}
]
}| Field | Value | Why it matters | |
|---|---|---|---|
Permanent browser ID | 25f060d7-de5f-427d-b184-44147d043970 | A UUID generated on first launch that never changes. It lets Google Analytics link every future event to your specific browser installation. | |
Session ID | 1780870378576 | A timestamp-derived ID that groups events within a 30-minute window. Resets if more than 30 minutes pass between events. | |
Event name and action | user_action / action: autostart | What you were doing when the event fired, e.g. installing the extension, starting the browser, or hitting an error. |
Service worker: getOrCreateClientId and sendEvent
// service_worker.js line 2536-2596
getOrCreateClientId {
const { clientId } = await chrome.storage.local.get('ClientId');
if (typeof clientId === 'string') return clientId;
const uuid = self.crypto.randomUUID;
await chrome.storage.local.set({ ClientId: uuid });
return uuid;
}
sendEvent(event) {
const [clientId, sessionId] = await Promise.all([
this.getOrCreateClientId,
this.getOrCreateSessionId
]);
const payload = {
client_id: clientId,
events: [{ name: event.name, params: { session_id: sessionId, engagement_time_msec: 100, ...event.params } }]
};
await fetch(
'https://www.google-analytics.com/mp/collect?measurement_id=G-XCPV2XK66M&api_secret=<redacted>',
{ method: 'POST', body: JSON.stringify(payload) }
);
}- www.google-analytics.com
Google Analytics Measurement Protocol endpoint. Receives the permanent client_id, session_id, and event metadata, processed by Google LLC under its analytics terms of service.
Account auto-created on install; device ID and IP sent to remote API
A POST fires on install, creating an account on the operator's server with your device ID and public IP before interaction begins.
The server address comes from a GCS JSON file, so the operator can redirect it anytime, unannounced.
You install the extension.
No further action is needed, the registration call fires during the install event handler.
The extension creates an account on the operator's server using your device ID and public IP address.
The registration target is resolved from a remote config file, so it can be changed by the operator without an extension update.
| Content-Type | application/json |
{
"deviceId": "c4815874-fd71-4c08-9ab1-082a3d4aed6f",
"deviceIp": "203.0.113.47"
}| Field | Value | Why it matters | |
|---|---|---|---|
Device identifier | c4815874-fd71-4c08-9ab1-082a3d4aed6f | A UUID generated by the extension that uniquely identifies your device across sessions. Sent on every subscription check after registration. | |
Public IP address | 203.0.113.47 | Your device's public IP address at the time of install. This reveals your approximate location and network provider. |
Install handler: remote config fetch then createNewUser call
// service_worker.js line ~4924-4937 (runtimeOnInstalledListener)
if (event.reason === 'install') {
await initDeviceId;
const { userId } = await chrome.storage.local.get('UserId');
const { userId: cookieUserId } = await loadUserIdFromCookie(cookieDomain);
if (!userId && !cookieUserId) {
// Fires createNewUser — no consent prompt
await createNewUser(ModeEnum.New, { isGuestMode: true, isSaleActive: false, isTrial: false });
}
}
// service_worker.js line ~1356-1361 (createNewUser endpoint)
const CREATE_NEW_USER_PATH = 'premium/api/v1/uboost-premium/create-new-user';
// apiBaseUrl comes from otkryvashka.json fetched from GCS:
// https://storage.googleapis.com/otkryvashka/otkryvashka.json- storage.googleapis.com
Operator-controlled GCS bucket. Hosts otkryvashka.json, supplying the current apiBaseUrl; the operator can edit it to redirect registration calls to any server.
- opener.website
Primary API server (apiBaseUrl resolved at runtime). Receives device ID, public IP on install; receives userId + deviceId + deviceIp on each subsequent subscription check.
What it can do
Permissions this extension asks for, as declared in version 1.7.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on youtube.com
https://*.youtube.com/*
Read and change your data on youtu.be
https://*.youtu.be/*
Read and change your data on googlevideo.com
https://*.googlevideo.com/*
Read and change your data on play.google.com
https://*.play.google.com/*
Read and change your data on ytimg.com
https://*.ytimg.com/*
Read and change your data on witch.tv
https://*.witch.tv/*
Read and change your data on staticfiles.cukubst.top
https://staticfiles.cukubst.top/*
Read and change your data on uboost.space
https://uboost.space/*
Read and change your data on ubst.space
https://ubst.space/*
Read and change your data on sentry-ws-1.vpnn.space
*://sentry-ws-1.vpnn.space/*
Read and change your data on vpnn.loan
*://*.vpnn.loan/*
Read and change your data on yandexcloud.net
*://*.yandexcloud.net/*
Read and change your data on every site you visit
<all_urls>
Route all of your browsing through a server of its choosing
proxy
Store data in your browser
storage
Watch every request your browser makes
webRequest
Act on the current tab, but only after you click the extension
activeTab
See the address and title of every tab you have open
tabs
Schedule its own background tasks
alarms
See, disable and uninstall your other extensions, including your security ones
management
Read and change cookies, including the ones that keep you signed in
cookies