737 Chrome VPN Extensions Found Routing Traffic Through Proxies

A significant number of Chrome VPN and proxy extensions have been identified as routing user traffic through potentially malicious proxies, primarily targeting Russian-speaking users.

A substantial collection of 737 free VPN and proxy extensions has been discovered to be routing user traffic through proxy servers, primarily affecting Russian-speaking individuals seeking access to restricted services. These extensions, which have accumulated 75,486 installs, were published under at least 40 developer accounts on the Chrome Web Store.

Impersonation of Established Brands

Among the identified extensions, 274 were found to impersonate 66 well-known VPN and privacy brands, including Proton VPN, NordVPN, and ExpressVPN. Security researcher Kush Pandya noted that these extensions route users’ entire browser sessions through SOCKS5 proxies operated by a single provider, with 520 of the 522 extensions in the analyzed set using the same proxy infrastructure.

Technical Details of the Threat

The majority of these extensions configure the browser to use a fixed SOCKS5 server on port 1082, placing the threat actor in an adversary-in-the-middle (AitM) position. This setup allows them to monitor browser destinations, source IP addresses, and any HTTP request bodies. Additionally, the extensions include a bypass list that only permits loopback addresses, ensuring that all other traffic is funneled through the SOCKS5 relay.

Current Status and Actions Taken

As a result of these findings, 221 browser add-ons have been removed from the Chrome Web Store, while 516 extensions remain active. The threat actor behind these extensions is believed to be operating a subscription VPN business in Russia, as indicated by a taxpayer number and other identifiable information.

Concerns and Red Flags

Several concerning practices have been noted, including the advertisement of non-existent premium features, evasion of DNS-over-HTTPS blocklists, and the submission of false statements during the Chrome Web Store review process. The extensions also feature internal documentation suggesting methods to avoid detection by Chrome’s policies.

In summary, while the functionality of these extensions may appear similar to legitimate VPN services, their deceptive practices and potential for traffic interception pose significant risks to users.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 349