- 737 malicious Chrome extensions, impersonating 66 VPN brands like NordVPN and Proton VPN, routed Russian users’ browser traffic through a single SOCKS5 proxy infrastructure.
- Over 200 extensions were removed from the Chrome Web Store, but 516 remain active, with the threat actor operating a subscription VPN business in Russia.
- The extensions bypassed store policies using fake interfaces, post-approval code changes, and identical false statements, while a separate AI extension resurfaced with a monetization scheme.
A massive set of 737 free VPN and proxy extensions primarily targeted Russian-speaking users seeking access to blocked services, aiming to intercept browser traffic and route it through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs and impersonated 66 established brands, including Proton VPN, NordVPN, and Surfshark, according to Socket reported.
Security researcher Kush Pandya stated that 520 of the 522 extensions in the bulk corpus route browser traffic through the same SOCKS5 infrastructure, placing the threat actor in an adversary-in-the-middle position. Every extension that configures a proxy also includes a bypass list limited to loopback addresses, funneling all other requests through the relay on port 1082.
As many as 221 browser add-ons have been removed from the Chrome Web Store, while the remaining 516 extensions remain active. The threat actor is believed to run a subscription VPN business in Russia, based on a leaked taxpayer number and Windows build path revealing a development folder structure.
The extensions exhibited multiple red flags, including advertising nonexistent paid tiers, failing every connection attempt while showing a fake interface, and shipping an internal manual instructing developers to avoid placing domains directly in proxy settings. Additionally, the extensions added a remote-configuration layer after extension approval and attempted to game the Chrome Web Store review process with identical false justifications.
Meanwhile, Netskope Threat Labs highlighted the return of a Chrome extension named “AI Sidebar with Deepseek, ChatGPT, Claude, and more,” months after its removal for prompt poaching. The extension released a benign update removing data theft code, then later pushed a monetization payload that opens an affiliate link in a foreground tab upon every update and uninstall event.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- Memory Chip Cycle Nears End, Micron and SK Hynix Face Dip
- Cheapest Singapore VPS That Is Actually Worth Buying: 2026 Price Comparison
- CFTC shields Kalshi from NY as revenue doubles
- 99.7% of XRP reserve drained in Coreum bridge hack
- Binance, RedotPay clash over end of Singapore case in $473M Hong Kong battle
