Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider.

Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver.

Researchers at application security company Socket found that the campaign relied on 40 publisher accounts and used a shared analytics account.

While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country.

“With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP,” Socket explains.

The researchers identified three threat behaviors associated with the campaign:

Socket could not analyze the code in all of the extensions because 212 of them had already been removed when the researchers collected them.

Based on the strings found, the campaign appears to be an attempt to funnel customers to a subscription-based VPN service in Russia.

The researchers noted that the mechanism used by the extensions appears no different from that of a legitimate service, but they identified several indicators of intentional deception:

Socket says that while Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome’s Web Store.

Socket has published the IDs of all extensions linked to the campaign and recommends that users check their browsers for any of them and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Google Chrome may soon block New Tab hijacker extensions by default

Fake Perplexity extension on Chrome Web Store tracked searches

Adobe Chrome extension flaw let sites access private WhatsApp chats

Malicious Edge extension abuses Native Messaging as bridge to malware

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

LexisNexis shuts down services after suspicious activity on servers

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Overdue a password health-check? Audit your Active Directory for free

Overdue a password health-check? Audit your Active Directory for free

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.