Breaking
Cyber CrimeConfirmed

Fake VPN Extensions Hijack Traffic

Hundreds of malicious Chrome extensions impersonate VPNs, routing user traffic through a proxy.

··1 hour ago·2 min read
graphical user interface, text, application
Photo by Nebular on Unsplash

More than 737 extensions on the Chrome Web Store were found impersonating well-known VPN and proxy services, directing users’ traffic through a single proxy provider. The campaign, which researchers believe targeted Russian users, downloaded the extensions nearly 75,000 times before many were removed. But over 500 remain available.

Impersonating Trusted Brands

The extensions posed as legitimate services like Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 DNS resolver. According to researchers at application security firm Socket, the operation was run through 40 publisher accounts and used a shared analytics account, suggesting a coordinated effort.

Socket’s analysts found that the extensions were designed to route all browser traffic through the operator’s SOCKS5 proxies on port 1082. This gave the attacker a position to intercept data, as the researchers noted: “With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP.”

Three Threat Behaviors

The research identified three specific behaviors across the extensions. First, 520 extensions configured Chrome to route traffic through the proxy. Second, 104 extensions resolved their proxy hostnames via Cloudflare or Google DNS-over-HTTPS, hiding the operator’s domain from inspection. Finally, some extensions advertised premium servers in Japan, Singapore, Canada, Australia, and Turkey that did not exist, likely for subscription fraud.

Deceptive Tactics

Socket’s analysis revealed signs of intentional deception, despite the extensions appearing to work like legitimate VPNs. These indicators included impersonation of established brands, nonexistent premium server locations, nonfunctional payment or connection mechanisms, misleading disclosures to store reviewers, and adding remote configuration after approval. The extensions also used techniques to hide proxy destinations from analysis.

Targeting Russian Users

Many of the downloads came from Russian users, who often seek tools to bypass blocked services in their country. The campaign appeared to be an attempt to funnel customers to a subscription-based VPN service in Russia, based on strings found in the extensions. Socket could not analyze 212 extensions because they were removed before collection.

Still Available in Web Store

While Google removed more than 200 related extensions, over 500 remain accessible. Socket has published the IDs of all linked extensions and urges users to check their browsers and remove any that are present. Users should also ensure Chrome’s proxy configuration is reset to normal.

What This Means

This incident highlights the risk users face when installing browser extensions, even those that appear to be from trusted sources. For organizations, it underscores the need to monitor browser extensions and enforce policies that restrict installations to verified sources. For individuals, it suggests caution: always verify an extension’s legitimacy, check its permissions, and be wary of downloads that promise to bypass restrictions. The persistence of so many malicious extensions shows that the Chrome Web Store’s review process can be bypassed, leaving users vulnerable to data interception.

#chrome extensions#vpn#malware#socks5#proxy#socket

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories