Fake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers
A campaign involving 31 Russian-language Chrome extensions, posing as VPNs, has been discovered to hijack user browser traffic, routing it through remote proxy servers controlled by operators.

A coordinated cluster of 31 Russian-language Chrome extensions, masquerading as VPN services, has been identified for secretly redirecting user browser traffic through remotely controlled proxy infrastructure. Disclosed by Risky Plugins on September 19, 2026, this campaign was active at the time of reporting and had amassed approximately 356,000 installations, granting its operators a significant footprint for traffic manipulation.
The extensions, which target users seeking access to blocked or restricted services, employ names associated with popular platforms such as RuTracker, YouTube, Telegram, Instagram, ChatGPT, Netflix, and Discord. Investigators linked the malicious extensions to three distinct publisher accounts, noting that all 31 extensions share a common underlying codebase. The most popular among them, "RuTracker VPN," alone accounted for an estimated 200,000 installations.
Analysis revealed that each extension requests Chrome's powerful proxy permission and registers a webRequest authentication handler, granting it host access across all URLs. This allows the extensions to manage browser proxy settings and observe or intercept network requests. Once installed, the extension configures a Proxy Auto-Configuration (PAC) script that dictates whether a requested URL should connect directly or be routed through a designated proxy server.
A critical aspect of this campaign is that the proxy target list is not hardcoded within the extension. Instead, it is dynamically downloaded from external infrastructure. This enables the operators to modify which websites are proxied and which servers receive the traffic without needing to push an update to the extension, making detection and mitigation more challenging.
The server list was found to be concealed using a Caesar cipher applied over Base64, a rudimentary obfuscation technique that offers minimal protection against determined analysis. Decoded data revealed shared proxy credentials with monthly expiration dates, and a paid VIP service was also offered through specific URLs. While most extensions appeared designed to proxy traffic for specific promoted services, the "Total VPN" variant was observed routing all browser traffic, significantly increasing the potential for exposure.
Operators of these proxy servers can potentially monitor connection metadata and destinations. Furthermore, unencrypted HTTP content may be inspected or altered. While HTTPS encrypts page content, routing sessions through unknown infrastructure creates opportunities for monitoring, blocking, redirection, and other downstream abuses.
Risky Plugins archived and analyzed the CRX packages for 28 of the 31 extensions, providing SHA-256 hashes to aid in detection. The report also noted that several fallback hostnames associated with this campaign matched names previously linked to premium servers of the legitimate Browsec VPN service, though this was presented as an investigative lead rather than definitive proof of attribution.
Users are strongly advised to remove any of the identified extensions immediately, restart their browsers, and review their proxy settings for unfamiliar entries. Changing credentials for sensitive accounts used during the exposure window and monitoring for suspicious logins is also recommended. Enterprise defenders should block the identified extension IDs, configuration domains, and subscription hosts, and investigate outbound connections to the listed suspicious domains.