737 Chrome VPN Extensions Caught Routing Traffic Through Single Proxy Infrastructure
Researchers at Socket identified 737 free VPN and proxy extensions on the Chrome Web Store โ published across at least 40 developer accounts and totalling 75,486 installs โ that intercept and route users' entire browser sessions through SOCKS5 proxies operated by a single provider, primarily targeting Russian-speaking users seeking access to blocked services.
Key Facts
| Attribute | Detail |
|---|---|
| Scale | 737 extensions, 40+ developer accounts, 75,486 installs |
| Impersonation | 274 extensions impersonated 66 established brands (Proton VPN, NordVPN, Surfshark, ExpressVPN, Google Outline, etc.) |
| Infrastructure | 520 of 522 analysed extensions routed traffic through the same SOCKS5 infrastructure |
| Risk | Full-session traffic interception, credential and activity exposure |
| Primary targets | Russian-speaking users seeking censorship circumvention |
Context
The campaign is a supply-chain abuse of the extension distribution channel: fake VPN tools that work as advertised at the network level while harvesting everything that passes through them. It is a reminder that "free VPN" extensions are a recurring malware and privacy vector, and that extension permissions deserve the same scrutiny in AU/NZ organisations as any third-party software. The takeaway for defenders: audit browser extension inventories and block unknown VPN/proxy extensions on managed devices.
Related Pages
- Malicious Litellm Releases Tied To Trivy Hack May Have Exposed 2 100 Organisatio โ same-week software supply-chain compromise
- Long Running Data Theft Campaign Targeting Salesforce And Servicenow โ credential-harvesting wave
Sources: raw/digests/Cyber-Digest-2026-08-13