Back to Feed
MalwareAug 12, 2026

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

737 Chrome VPN extensions found to intercept traffic and route it through proxies.

Summary

A large number of 737 free VPN and proxy Chrome extensions have been discovered impersonating legitimate brands to target Russian-speaking users. These extensions secretly route all browser traffic through a single SOCKS5 proxy infrastructure, allowing threat actors to intercept sensitive data. While some have been removed, many remain active, with evidence suggesting the operators run a subscription VPN business in Russia.

Full text

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One Ravie LakshmananAug 12, 2026Browser Security / Privacy A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, and Google's Outline, per Socket. The censorship circumvention extensions "route the user's entire browser session through SOCKS5 proxies operated by a single provider," security researcher Kush Pandya said. "520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure." The vast majority of the extensions have been found to route users' entire browser sessions by setting "chrome.proxy.settings" to a fixed SOCKS5 server on port 1082, placing the threat actor in an adversary-in-the-middle (AitM) position to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP. Every extension that configures a proxy also comes with a bypass list that only includes loopback addresses (i.e., the localhost or 127.0.0.1"), meaning every other browser request is funnelled through the SOCKS5 relay on port 1082 once the user connects to the purported VPN service. As many as 221 browser add-ons have been removed from the Chrome Web Store, while the remaining 516 extensions have been listed as active. The threat actor is said to be running a subscription VPN business in Russia, based on a 12-digit taxpayer number and the fact that some of them leak their Windows build path ("C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\<domain>\<product>\<product>-release.zip"). Ideally, the functionality is no different from a legitimate VPN or proxy service. The defining aspect of this activity is its attempt to impersonate established brands as opposed to offering it under their own name. Some of the other red flags include - Advertising paid tiers (or premium locations) that do not exist DNS-over-HTTPS blocklist evasion Failing every connection attempt while showing a complete fake interface, including a working connecting animation and status indicator Shipping an internal manual named "Промт для сотрудников" (translated to "Prompt for employees") that instructs them to avoid putting the domain directly into "chrome.proxy.settings" (and instead provide only the resolved IP) and refrain from using a domain from another extension without separate instructions Presence of comments that indicate a deliberate attempt to evade Chrome Web Store policies Adding a new remote-configuration layer after extension approval Attempts to game the Chrome Web Store review process by submitting identical justifications, stating "No data transmitted to external servers" or "No user tracking or logging" "For each affected user, while the extension is connected, every request passes through a server the threat actor controls," Pandya said. "Whether the threat actor owns those proxy servers or resells capacity from an upstream provider is not resolvable from the extension code. If it resells, a further party is in the same position." "What is established from the packages and from public infrastructure is the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and the post-approval code substitution." Removed Chrome Extension Resurfaces with Monetization Scheme The development comes as Netskope Threat Labs highlighted the return of a Google Chrome extension named "AI Sidebar with Deepseek, ChatGPT, Claude, and more." months after it was removed for engaging in Prompt Poaching tactics. The clean-then-poisoned update sequence, spread across versions 1.7.2.0 and 1.7.3.0, took place via Google's CRX content delivery network on July 31, 2026, pushing out a monetization scheme – a "surgical" 21-line addition – built around extension update and uninstall events. "The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks, it pulled the rug again with a new update," the cybersecurity company said. "While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Adversary-in-the-Middle, browser security, chrome security, Impersonation, Malicious Extension, Privacy, Proxy Security, Threat Intelligence, VPN Security, Web Security ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources See How to Stop the Browser-Based Attacks Your Existing Stack Misses [Book a Live Demo] [Webinar] See Where Claude Fits in the SOC and Where It Falls Short at Scale Defend Against One-Click AI Memory Poisoning — Download the Cheat Sheet Benchmark Your Defenses Against 338M+ Attack Simulations — Download the Blue Report 2026

Indicators of Compromise

  • ip — 127.0.0.1
  • malware — chrome.proxy.settings

Entities

Chrome (product)Proton VPN (product)NordVPN (product)Surfshark (product)AdGuard VPN (product)ExpressVPN (product)