Hundreds of fake Chrome VPN extensions route traffic through a proxy
by Bill Toulas · BleepingComputerMore than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider.
Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver.
Researchers at application security company Socket found that the campaign relied on 40 publisher accounts and used a shared analytics account.
While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country.
“With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP,” Socket explains.
The researchers identified three threat behaviors associated with the campaign:
- 520 extensions configured Chrome to route all browser traffic through the operator’s SOCKS5 proxies on port 1082.
- 104 extensions resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS to protect the operator’s domain from scrutiny.
- Extensions that advertised non-existent premium servers in Japan, Singapore, Canada, Australia, and Turkey for subscription fraud
Socket could not analyze the code in all of the extensions because 212 of them had already been removed when the researchers collected them.
Based on the strings found, the campaign appears to be an attempt to funnel customers to a subscription-based VPN service in Russia.
The researchers noted that the mechanism used by the extensions appears no different from that of a legitimate service, but they identified several indicators of intentional deception:
- impersonating well-known brands
- advertising nonexistent premium server locations
- nonfunctional payment or connection mechanisms
- misleading disclosures to store reviewers
- adding remote configuration after the extension was approved
- the use of techniques to hide proxy destinations from analysis
Socket says that while Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome's Web Store.
Socket has published the IDs of all extensions linked to the campaign and recommends that users check their browsers for any of them and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.