Hundreds of Chrome VPN extensions secretly shunt traffic to one proxy

Socket finds 737 VPN and proxy add-ons funneling browser sessions through a single provider.

CSBadmin
1 Min Read

Socket researchers found 737 free VPN and proxy add-ons that hijack browser traffic and forward it through one provider’s proxy infrastructure. Spread across at least 40 Chrome Web Store developer accounts, the extensions reached 75,486 installs and focus on Russian-speaking users trying to reach blocked services.

Some 274 of the extensions pose as 66 well-known VPN and privacy brands, from Proton VPN and NordVPN to Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1. Nearly all pin chrome.proxy.settings to one SOCKS5 server on port 1082, which puts the operator in an adversary-in-the-middle spot where browser destinations, source IPs, TLS SNI values, and unencrypted request bodies are all visible.

Google has removed 221 of the extensions, while 516 remain listed as active. Red flags include non-existent paid tiers, fake connection interfaces, post-approval code substitution, and review submissions falsely claiming no data is transmitted to external servers.

Users should audit installed extensions, remove anything impersonating a known VPN brand, and install browser add-ons only from official vendor listings. For each affected user, every request passes through a server the threat actor controls while the extension is connected.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.