Security researchers from the company Socket found out 737 malicious extensions within the catalog of Chrome Web Store. The add-ons, disguised as renowned privacy protection services such as Proton VPN, NordVPN, Surfshark, ExpressVPN and Cloudflare 1.1.1.1, totaled almost 75,000 downloads. The campaign mainly targeted users located in Russia, intending to overcome restrictions on access to online content.
The entire operation is headed by 40 separate developer accountsbut attributable to a single malicious actor who shared a common analytical profile. On a technical level, well 520 extensions they reconfigured the browser to route all web traffic to SOCKS5 proxy server attested on port 1082. This architecture allowed infrastructure managers to intercept source IP addresses, destination domains, TLS SNI information and the content of unencrypted HTTP requests.
Fake and malicious extensions also on the Chrome Web Store: better be careful
To hide the underlying infrastructure from analysts, 104 extensions they resolved hostnames via DNS-over-HTTPS using Cloudflare and Google resolvers. Developers employed evasive techniques to bypass the platform’s automatic checks, providing misleading information to reviewers and triggering security features. remote configuration only after obtaining initial approval. Socket’s detailed analysis highlighted how the actual destinations of the proxies were knowingly hidden from the public.
In addition to data theft, the operation aimed at direct financial gain by pushing users to purchase paid subscriptions. The extensions interface advertised access to premium VPN server located in territories such as Japan, Singapore, Canada, Australia and Türkiye. Sponsored connections were completely non-existent and structured to direct users towards one Russian VPN platform managed by the same promoters of the scam.
Google’s removal process proved partial. The Mountain View giant eliminated further 200 malicious add-onsbut more than 500 extensions compromised were still downloadable at the time of publication of the report. A group of 212 extensions instead it disappeared before the source code was extracted. Anyone who has installed one of these components must proceed with immediate uninstallation and manually check the proxy configuration in the software settings.

