← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Hundreds of Fake Chrome VPN Extensions Route User Traffic Through Proxies

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 737 fake Chrome VPN extensions identified.
  • Extensions routed traffic via a single SOCKS5 proxy infrastructure.
  • Impersonated 66 legitimate VPN brands.
  • Nearly 75,000 installs, mainly by Russian users.
  • Allowed observation of browser destinations and user data.

Discovery of Malicious Extensions

Security researchers have uncovered a large network of 737 free VPN and proxy extensions for Google Chrome that were routing user traffic through a centralized SOCKS5 proxy infrastructure. These extensions were published across at least 40 Chrome Web Store developer accounts and accumulated 75,486 installs.

Impersonation and Targeting

A significant portion of these extensions, 274 of them, impersonated 66 established VPN and privacy brands. These included well-known services such as Proton VPN, NordVPN, Surfshark, ExpressVPN, CyberGhost, Windscribe, TunnelBear, AdGuard VPN, Cloudflare's 1.1.1.1, and Google's Outline. The campaign primarily targeted Russian-speaking users seeking to bypass internet restrictions and access blocked services.

Traffic Interception Mechanism

The extensions were designed to route the user's entire browser session through SOCKS5 proxies operated by a single provider. Specifically, 520 of the 522 extensions in the bulk corpus configured Chrome to route all browser traffic by setting "chrome.proxy.settings" to a fixed SOCKS5 server on port 1082. This setup placed the threat actor in an adversary-in-the-middle (AitM) position, enabling them to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP.

Potential Risks to Users

By intercepting browser traffic, the operators of these proxies could potentially monitor user browsing activity and access sensitive data. This incident highlights the risks associated with unverified browser extensions and the potential for data interception when using services that claim to offer privacy or circumvention without proper vetting.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Security researchers discovered over 737 malicious Chrome extensions impersonating VPN services, which routed user traffic through SOCKS5 proxies controlled by a single operator. These extensions, downloaded nearly 75,000 times, primarily targeted Russian users seeking to bypass internet restrictions, exposing their browsing data to potential interception. The campaign highlights ongoing risks within browser extension ecosystems and the need for vigilance against deceptive software.

Security researchers identified 737 Chrome VPN extensions, primarily targeting Russian-speaking users, that route browser traffic through a single SOCKS5 proxy infrastructure. These extensions, many impersonating legitimate VPN brands, allow an adversary-in-the-middle to observe user browsing activity and data. This incident highlights the risks associated with unverified browser extensions and the potential for data interception.