Hundreds of Fake Chrome VPN Extensions Caught Hijacking User Traffic
A widespread campaign involving over 737 malicious browser extensions impersonated popular VPN services on the **Chrome Web Store**, routing user traffic through attacker-controlled SOCKS5 proxies. Discovered by **Socket** researchers, these extensions were downloaded nearly 75,000 times, predominantly by users seeking to bypass geo-restrictions.
More than 737 browser extensions, masquerading as legitimate VPN and proxy services, have been found on the **Chrome Web Store**. These deceptive extensions funneled user traffic through SOCKS5 proxies operated by a single, undisclosed provider.
### Impersonating Major VPN Brands
The malicious extensions mimicked numerous established brands, including **Proton VPN**, **NordVPN**, **Surfshark**, **ExpressVPN**, and even **Cloudflare's 1.1.1.1** public DNS resolver.
Researchers at application security company **Socket** identified the campaign, noting its reliance on 40 distinct publisher accounts and a shared analytics account.
### Significant Downloads and Targeted Users
While active on the **Chrome Web Store**, these extensions accumulated nearly 75,000 downloads. The primary target audience appeared to be Russian users seeking tools to circumvent blocked services within their country.
According to **Socket**, "With all browser traffic forced through it [the relay], the threat actorβs server is positioned to read every destination, every TLS SNI value, the victimβs source IP, and any request body sent over plain HTTP."
### Malicious Behavior Uncovered
**Socket** researchers pinpointed three key threat behaviors associated with the campaign:
* 520 extensions were configured to route all browser traffic through the operatorβs SOCKS5 proxies on port 1082.
* 104 extensions resolved their proxy hostnames via **Cloudflare** or **Google DNS-over-HTTPS** to conceal the operator's domain from scrutiny.
* Some extensions advertised non-existent premium servers in locations like Japan, Singapore, Canada, Australia, and Turkey, suggesting potential subscription fraud.
It's worth noting that 212 of the extensions were already removed when researchers collected them, preventing full code analysis for all.
### Indicators of Intentional Deception
While the mechanism used by these extensions bore some resemblance to legitimate services, **Socket** identified several clear indicators of intentional deception:
* Impersonation of well-known brands.
* Advertising non-existent premium server locations.
* Non-functional payment or connection mechanisms.
* Misleading disclosures provided to store reviewers.
* Adding remote configuration capabilities after initial extension approval.
* Employing techniques to hide proxy destinations from analysis.
### Ongoing Threat and User Recommendations
Despite **Google** removing over 200 of the identified extensions, **Socket** reports that more than 500 still remain available in the **Chrome Web Store**.
**Socket** has published the IDs of all extensions linked to this campaign. Users are strongly advised to check their browsers for any of these identified extensions and remove them immediately if found. Furthermore, users should confirm that **Chrome's** proxy configuration has reverted to its normal state after removal.
