Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [incident, browser-extension, chrome, vpn, proxy, supply-chain, privacy, socket] ยท confidence: high ยท affected_sectors: [technology, retail, government, finance] ยท au_impact: true

737 Chrome VPN Extensions Caught Routing Traffic Through Single Proxy Infrastructure

Researchers at Socket identified 737 free VPN and proxy extensions on the Chrome Web Store โ€” published across at least 40 developer accounts and totalling 75,486 installs โ€” that intercept and route users' entire browser sessions through SOCKS5 proxies operated by a single provider, primarily targeting Russian-speaking users seeking access to blocked services.

Key Facts

Attribute Detail
Scale 737 extensions, 40+ developer accounts, 75,486 installs
Impersonation 274 extensions impersonated 66 established brands (Proton VPN, NordVPN, Surfshark, ExpressVPN, Google Outline, etc.)
Infrastructure 520 of 522 analysed extensions routed traffic through the same SOCKS5 infrastructure
Risk Full-session traffic interception, credential and activity exposure
Primary targets Russian-speaking users seeking censorship circumvention

Context

The campaign is a supply-chain abuse of the extension distribution channel: fake VPN tools that work as advertised at the network level while harvesting everything that passes through them. It is a reminder that "free VPN" extensions are a recurring malware and privacy vector, and that extension permissions deserve the same scrutiny in AU/NZ organisations as any third-party software. The takeaway for defenders: audit browser extension inventories and block unknown VPN/proxy extensions on managed devices.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13