[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOJnAetQWSXl7tp3ItWcb_unTmJFyR3LJdRSdtpoztzg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"85eaf2fd-9ef1-4546-886d-721b528a7647","737-fake-chrome-vpn-extensions-hijack-browser-traffic-via-socks5-proxies","3c8844b2-213d-475b-a52e-4a2219d9edcb","737 Fake Chrome VPN Extensions Hijack Browser Traffic via SOCKS5 Proxies","This campaign exploited users' trust in recognizable VPN brand names by publishing hundreds of impersonator extensions on the Chrome Web Store, funneling all browser traffic through attacker-controlled SOCKS5 proxies. The root problem is a combination of insufficient user awareness about extension vetting and weak supply chain controls in browser extension marketplaces. Once installed, these extensions silently intercept communications, enabling credential theft, traffic manipulation, and subscription fraud without any visible warning to the user. The scale — 737 extensions and 75,000+ installs — demonstrates how low the barrier is for threat actors to abuse open publishing platforms. This matters because browser extensions operate with elevated trust and broad permissions, making them a high-value, low-visibility attack vector.","**Immediate actions:**\n- Audit all browser extensions installed across your organization and remove any unverified or brand-impersonating VPN\u002Fproxy tools immediately.\n- Block installation of extensions not approved via a managed allowlist using browser policy (e.g., Google Workspace or Chromium enterprise policies).\n\n**Long-term improvements:**\n- Establish a formal extension vetting process that verifies publisher identity, reviews requested permissions, and cross-checks against known-good sources before approving for organizational use.\n- Educate employees on how to identify browser extension impersonation, including checking publisher names, install counts, reviews, and permission scopes before installation.\n- Integrate browser extension inventory into your asset management and vulnerability management programs for continuous visibility.\n\n**Detection measures:**\n- Monitor network traffic for unexpected SOCKS5 proxy connections or unusual outbound routing patterns that may indicate browser-level traffic redirection.\n- Deploy endpoint detection tools capable of flagging newly installed or unapproved browser extensions across managed devices in near real-time.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 SA-12: Supply Chain Protection","GDPR Article 32: Security of Processing (data interception risk)","NIST CSF PR.AT-1: Awareness and Training","NIST CSF DE.CM-7: Monitoring for Unauthorized Activity","published","2026-08-12T02:20:39.981265+00:00","2026-08-12T02:20:39.599+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fchrome-vpn-extension-impersonation?utm_medium=feed","737-chrome-vpn-extensions-linked-to-brand-impersonation-and-browser-traffic-redi-ec2c71","737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"17063c1f-4b80-4c94-9a59-e78dcd960c59","2026-08-12","morning","ThreatNoir Morning Brief — August 12","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-12\u002Fthreatnoir-morning-brief-2026-08-12.mp3"]