737 Fake Chrome VPN Extensions Hijack Browser Traffic via SOCKS5 Proxies
This campaign exploited users' trust in recognizable VPN brand names by publishing hundreds of impersonator extensions on the Chrome Web Store, funneling all browser traffic through attacker-controlled SOCKS5 proxies. The root problem is a combination of insufficient user awareness about extension vetting and weak supply chain controls in browser extension marketplaces. Once installed, these extensions silently intercept communications, enabling credential theft, traffic manipulation, and subscription fraud without any visible warning to the user. The scale — 737 extensions and 75,000+ installs — demonstrates how low the barrier is for threat actors to abuse open publishing platforms. This matters because browser extensions operate with elevated trust and broad permissions, making them a high-value, low-visibility attack vector.
Tactical Insight
Immediate actions
- Audit all browser extensions installed across your organization and remove any unverified or brand-impersonating VPN/proxy tools immediately.
- Block installation of extensions not approved via a managed allowlist using browser policy (e.g., Google Workspace or Chromium enterprise policies).
Long-term improvements
- Establish a formal extension vetting process that verifies publisher identity, reviews requested permissions, and cross-checks against known-good sources before approving for organizational use.
- Educate employees on how to identify browser extension impersonation, including checking publisher names, install counts, reviews, and permission scopes before installation.
- Integrate browser extension inventory into your asset management and vulnerability management programs for continuous visibility.
Detection measures
- Monitor network traffic for unexpected SOCKS5 proxy connections or unusual outbound routing patterns that may indicate browser-level traffic redirection.
- Deploy endpoint detection tools capable of flagging newly installed or unapproved browser extensions across managed devices in near real-time.