Chrome: Over 70,000 users tricked by more than 700 fake VPN and proxy extensions

Written by Jason Miller

Security researchers from the company Socket found out 737 malicious extensions within the catalog of Chrome Web Store. The add-ons, disguised as renowned privacy protection services such as Proton VPN, NordVPN, Surfshark, ExpressVPN and Cloudflare 1.1.1.1, totaled almost 75,000 downloads. The campaign mainly targeted users located in Russia, intending to overcome restrictions on access to online content.

The entire operation is headed by 40 separate developer accountsbut attributable to a single malicious actor who shared a common analytical profile. On a technical level, well 520 extensions they reconfigured the browser to route all web traffic to SOCKS5 proxy server attested on port 1082. This architecture allowed infrastructure managers to intercept source IP addresses, destination domains, TLS SNI information and the content of unencrypted HTTP requests.

Fake and malicious extensions also on the Chrome Web Store: better be careful

To hide the underlying infrastructure from analysts, 104 extensions they resolved hostnames via DNS-over-HTTPS using Cloudflare and Google resolvers. Developers employed evasive techniques to bypass the platform’s automatic checks, providing misleading information to reviewers and triggering security features. remote configuration only after obtaining initial approval. Socket’s detailed analysis highlighted how the actual destinations of the proxies were knowingly hidden from the public.

In addition to data theft, the operation aimed at direct financial gain by pushing users to purchase paid subscriptions. The extensions interface advertised access to premium VPN server located in territories such as Japan, Singapore, Canada, Australia and Türkiye. Sponsored connections were completely non-existent and structured to direct users towards one Russian VPN platform managed by the same promoters of the scam.

Google’s removal process proved partial. The Mountain View giant eliminated further 200 malicious add-onsbut more than 500 extensions compromised were still downloadable at the time of publication of the report. A group of 212 extensions instead it disappeared before the source code was extracted. Anyone who has installed one of these components must proceed with immediate uninstallation and manually check the proxy configuration in the software settings.

Jason Miller

I'm Jason Miller, and I've been passionate about technology and storytelling for over a decade. As a lead writer at Herald Editorials, I strive to bring clarity and creativity to complex tech topics. When I'm not writing, you'll find me exploring the latest gadgets or hiking in the great outdoors.