VYPR
researchPublished Aug 12, 2026· 2 sources

Over 737 Fake Chrome VPN Extensions Hijack Browser Traffic

A widespread operation has compromised over 737 Chrome extensions, masquerading as free VPNs, to reroute user traffic through attacker-controlled SOCKS5 proxies.

Security researchers have uncovered a massive operation involving over 737 fake Chrome extensions, advertised as free VPNs and proxy tools, that secretly hijack user browser traffic. These malicious extensions, collectively installed more than 75,000 times, reroute web sessions through SOCKS5 proxy servers controlled by the attackers. This allows the operators to potentially monitor browsing activity, capture sensitive data, and expose users' source IP addresses.

The campaign is particularly concerning due to its scale and deceptive tactics. Researchers at Socket.dev identified the operation, noting that 274 of the extensions mimicked the branding of 66 legitimate VPN and privacy services, leading unsuspecting users to believe they were installing trusted software. Many of these fake extensions targeted Russian-speaking users seeking access to geo-restricted content and services.

The core functionality of these extensions was to configure Chrome to use a specific SOCKS5 proxy server. While the extensions claimed to offer privacy and access, their actual behavior was to funnel all browser traffic through the attacker-controlled infrastructure. This setup provided the threat actors with a vantage point to observe everything from visited websites to connection metadata, and in the case of unencrypted HTTP traffic, potentially the full content of user communications.

Adding to the sophistication of the campaign, the operators employed remote configuration updates in 66 of the extensions. This allowed them to change the underlying infrastructure or redirect traffic without requiring users to update the extension itself, making the malicious behavior persistent and harder to detect. This tactic mirrors previous campaigns where approved extensions later changed their risk profile, highlighting a significant gap between the perceived security and the actual network path.

While the researchers did not confirm that every byte of routed data was misused, the infrastructure's position was undeniably capable of observing user traffic. The extensions often requested only the 'proxy' permission, which, while seemingly limited, grants significant control over network traffic. Some extensions further obscured their activity by using encrypted DNS services to resolve proxy hostnames, reducing the visibility of standard DNS lookups.

The operation also exhibited signs of evasion and deception. Investigators found numerous advertised premium server locations that did not resolve, and some extensions displayed polished interfaces but were coded to fail all connection attempts. Misleading review documents falsely claimed no data was sent to external servers, directly contradicting the proxy-routing code. Google had removed 221 extensions at the time of reporting, but a significant number remained active.

Users who may have installed these extensions are advised to remove them immediately and review their browser's proxy settings. Organizations should conduct an inventory of installed extensions, monitor for unusual proxy configurations, and block the identified malicious domains and IP addresses at both DNS and network egress points. The persistent nature of such campaigns underscores the need for continuous vigilance and regular audits of browser extension permissions and network traffic.

This discovery is a stark reminder of the risks associated with free VPN and proxy services, especially those found on browser extension marketplaces. The ability of these extensions to impersonate legitimate services and leverage remote configuration for ongoing malicious activity poses a significant threat to user privacy and security.

This new report details that the malicious extensions, published across at least 40 developer accounts, accumulated over 75,000 installations. Furthermore, 274 of these extensions were found to impersonate 66 well-known VPN and privacy brands, including Proton VPN, NordVPN, and ExpressVPN, highlighting a sophisticated brand impersonation tactic.

Synthesized by Vypr AI