737 Chrome Extensions Were Hijacking Browser Traffic, 516 Remain Active

737 Chrome Extensions Were Hijacking Browser Traffic, 516 Remain Active

Nearly eight hundred free VPN extensions for Chrome turned out to be a traffic interception tool. Researchers uncovered 737 such add-ons that, instead of promised anonymity, routed users' entire browser traffic through proxy infrastructure controlled by attackers. Of those, 516 extensions are still listed as active in the Chrome Web Store, while only 221 have been removed.

The extensions were published from at least 40 different developer accounts in the Chrome Web Store and accumulated a total of 75,486 installs. The campaign specifically targeted Russian-speaking users seeking to bypass blocks, but in reality placed victims in an adversary-in-the-middle position. Among the discovered extensions, 274 impersonated 66 established privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare 1.1.1.1, and Google Outline.

The mechanics are simple and dangerous: the extensions set a fixed SOCKS5 server on port 1082 via the chrome.proxy.settings configuration. This allowed the operators to see visited site addresses, source IP addresses, TLS SNI values, and request bodies sent over unencrypted HTTP. The bypass list in each extension contained only loopback addresses (localhost and 127.0.0.1), meaning all other traffic was funneled through the proxy without exception.

Security researcher Kush Pandya noted that 520 of the 522 add-ons in the bulk sample used the same SOCKS5 infrastructure. Based on indirect evidence, including a 12-digit taxpayer identification number and build paths like C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\ \ \ -release.zip, the operators run a subscription VPN business in Russia.

Functionally, the extensions were no different from legitimate VPN services. The defining red flag was impersonating established brands rather than offering the service under their own name. Additional warning signs included paid tiers and premium locations that did not exist, attempts to evade DNS-over-HTTPS blocking, and a completely fake interface with a connection animation and status indicator while all connection attempts failed. The extensions also contained an internal manual named "Промт для сотрудников" (translated as "Prompt for employees").

Tags: Chrome
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate