CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Bleeping Computer Archived Aug 12, 2026 ✓ Full text saved

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]

Full text archived locally
✦ AI Summary · Claude Sonnet


    Hundreds of fake Chrome VPN extensions route traffic through a proxy By Bill Toulas August 12, 2026 02:54 PM 0 More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider. Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver. Researchers at application security company Socket found that the campaign relied on 40 publisher accounts and used a shared analytics account. While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country. “With all browser traffic forced through it [the relay], the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP,” Socket explains. The researchers identified three threat behaviors associated with the campaign: 520 extensions configured Chrome to route all browser traffic through the operator’s SOCKS5 proxies on port 1082. 104 extensions resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS to protect the operator’s domain from scrutiny. Extensions that advertised non-existent premium servers in Japan, Singapore, Canada, Australia, and Turkey for subscription fraud Socket could not analyze the code in all of the extensions because 212 of them had already been removed when the researchers collected them. Based on the strings found, the campaign appears to be an attempt to funnel customers to a subscription-based VPN service in Russia. The researchers noted that the mechanism used by the extensions appears no different from that of a legitimate service, but they identified several indicators of intentional deception: impersonating well-known brands advertising nonexistent premium server locations nonfunctional payment or connection mechanisms misleading disclosures to store reviewers adding remote configuration after the extension was approved the use of techniques to hide proxy destinations from analysis Socket says that while Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome's Web Store. Socket has published the IDs of all extensions linked to the campaign and recommends that users check their browsers for any of them and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Google Chrome may soon block New Tab hijacker extensions by default Fake Perplexity extension on Chrome Web Store tracked searches Adobe Chrome extension flaw let sites access private WhatsApp chats Malicious Edge extension abuses Native Messaging as bridge to malware Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
    💬 Team Notes
    Article Info
    Source
    Bleeping Computer
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗