Security researchers have uncovered a large network of 737 free VPN and proxy extensions for Google Chrome that were routing user traffic through a centralized SOCKS5 proxy infrastructure. These extensions were published across at least 40 Chrome Web Store developer accounts and accumulated 75,486 installs.
A significant portion of these extensions, 274 of them, impersonated 66 established VPN and privacy brands. These included well-known services such as Proton VPN, NordVPN, Surfshark, ExpressVPN, CyberGhost, Windscribe, TunnelBear, AdGuard VPN, Cloudflare's 1.1.1.1, and Google's Outline. The campaign primarily targeted Russian-speaking users seeking to bypass internet restrictions and access blocked services.
The extensions were designed to route the user's entire browser session through SOCKS5 proxies operated by a single provider. Specifically, 520 of the 522 extensions in the bulk corpus configured Chrome to route all browser traffic by setting "chrome.proxy.settings" to a fixed SOCKS5 server on port 1082. This setup placed the threat actor in an adversary-in-the-middle (AitM) position, enabling them to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP.
By intercepting browser traffic, the operators of these proxies could potentially monitor user browsing activity and access sensitive data. This incident highlights the risks associated with unverified browser extensions and the potential for data interception when using services that claim to offer privacy or circumvention without proper vetting.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers discovered over 737 malicious Chrome extensions impersonating VPN services, which routed user traffic through SOCKS5 proxies controlled by a single operator. These extensions, downloaded nearly 75,000 times, primarily targeted Russian users seeking to bypass internet restrictions, exposing their browsing data to potential interception. The campaign highlights ongoing risks within browser extension ecosystems and the need for vigilance against deceptive software.
Security researchers identified 737 Chrome VPN extensions, primarily targeting Russian-speaking users, that route browser traffic through a single SOCKS5 proxy infrastructure. These extensions, many impersonating legitimate VPN brands, allow an adversary-in-the-middle to observe user browsing activity and data. This incident highlights the risks associated with unverified browser extensions and the potential for data interception.