[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fE6lXoSggtgH4KmD8VwHLdIoJrT67v5zK57fHUw-ZJsk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"6cbb6c31-326c-4b32-b947-c48fa299a15b","fake-vpn-chrome-extensions-hijack-user-traffic-via-malicious-proxies","925cdf37-7a9a-410f-92fb-612fec70cc01","Fake VPN Chrome Extensions Hijack User Traffic via Malicious Proxies","Hundreds of counterfeit Chrome extensions impersonating legitimate VPN services were published to the Chrome Web Store and downloaded nearly 75,000 times before discovery. These extensions silently rerouted user traffic through attacker-controlled SOCKS5 proxies, exposing potentially sensitive browsing data and enabling subscription fraud. The attack exploits user trust in both well-known VPN brands and the perceived legitimacy of the official Chrome Web Store marketplace. This matters because users typically assume that extensions hosted on official stores have been vetted, making supply chain-style abuse of app marketplaces a highly effective social engineering vector.","**Immediate actions:**\n- Audit all installed browser extensions across your organization and remove any unverified or suspicious VPN-related extensions immediately.\n- Check network traffic logs for unexpected SOCKS5 proxy connections originating from endpoints.\n- Report and flag suspected malicious extensions to Google via the Chrome Web Store abuse reporting mechanism.\n\n**Long-term improvements:**\n- Enforce an organizational allowlist policy that restricts browser extension installations to a pre-approved set of verified tools.\n- Implement a software supply chain review process that includes third-party browser extensions as part of procurement and onboarding.\n- Train employees to verify the publisher identity, permissions requested, and user review patterns before installing any browser extension.\n\n**Detection measures:**\n- Deploy endpoint security or browser management tools (e.g., Google Workspace admin controls) to monitor and restrict extension installations centrally.\n- Configure network monitoring to alert on anomalous proxy traffic patterns, particularly to unknown SOCKS5 endpoints.\n- Regularly review installed extensions in your MDM or endpoint management platform to detect unauthorized or newly installed add-ons.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","GDPR Article 32: Security of Processing (data exposure risk)","NIST Cybersecurity Framework DE.CM-7: Monitoring for Unauthorized Activity","ITIL Service Configuration Management: Authorized Software Baseline","published","2026-08-12T20:20:22.540946+00:00","2026-08-12T20:20:22.24+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy\u002F","hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy-fb395f","Hundreds of fake Chrome VPN extensions route traffic through a proxy",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]