737 Fake Chrome VPN Extensions Route Traffic via Proxies
737 Chrome extensions impersonated VPN services while routing users' traffic through a single SOCKS5 proxy. Over 75,000 installs affected across the Store.
More than 737 extensions published to the Chrome Web Store have been caught impersonating legitimate VPN and proxy services while silently routing users’ browser traffic through a single SOCKS5 proxy operator, according to reporting from BleepingComputer and The Hacker News. The extensions racked up 75,486 installs before discovery, published across at least 40 developer accounts, with 274 confirmed to impersonate 66 named VPN services.
This is an organized operation — not a lone actor or a sloppy one-off.
What the Extensions Were Actually Doing
Users installed these expecting VPN protection or privacy routing. What they got was traffic rerouted through SOCKS5 proxies controlled by a single centralized provider — with no indication to the user that their traffic was going anywhere other than where they thought.
SOCKS5 is a legitimate proxy protocol. It’s also fully capable of forwarding all browser TCP connections through a remote server, making the entire browsing session visible to whoever controls the proxy endpoint. For users relying on these extensions to access geo-blocked services — the primary target audience appears to be Russian-speaking users circumventing content restrictions — that means their traffic was going to an operator they didn’t know existed instead of the VPN service they believed they’d installed.
Extension permissions make this clean from an attack surface perspective: the ability to intercept and proxy network requests is a standard, documented Chrome extension capability. There’s no exploit here. The fraud is in the impersonation.
Scope
- 737+ extensions on the Chrome Web Store
- 75,486 installs total
- 40+ developer accounts used to distribute them
- 274 extensions confirmed impersonating 66 named VPN services
- Targeting: primarily Russian-speaking users seeking access to blocked services
The multi-account, multi-extension structure is consistent with supply-chain-style infrastructure designed to survive partial takedowns — remove twenty accounts, fifty more are still live.
What to Do
Audit every Chrome extension on your browser right now. Go to chrome://extensions/. For anything claiming to be a VPN, proxy, or privacy tool, verify it against the provider’s official website before trusting it to stay installed.
What to look for:
- Verify the publisher. Legitimate VPN providers list their Chrome extension on their official site. If the extension’s developer name doesn’t match the VPN brand or has no verifiable company behind it, remove it.
- Check the install count and reviews. A VPN extension for a well-known brand with 300 installs and no reviews is suspicious — the real extensions from major providers have hundreds of thousands of installs and a review history.
- Check when it was published. A recently created developer account publishing a clone of a known brand is a red flag Chrome’s Web Store didn’t catch in time.
If you’ve been running one of these:
- Remove the extension immediately.
- Revoke and rotate any credentials you accessed in-browser while it was installed — assume your authenticated sessions were visible to the proxy operator.
- Clear cookies and browser storage. The session data the extension could observe includes any authenticated cookie set during that period.
For enterprise environments: browser extension governance is often missing or incomplete. An approved-extensions allowlist enforced via Chrome policies (Group Policy or MDM) would have stopped this entirely for managed endpoints. If that’s not in place, this is the incident that should change that.
Priority Call
If you or your users rely on browser-based VPN or proxy extensions for privacy or geo-unblocking, treat every installed extension in that category as unverified until confirmed. The scale of this operation — 40+ developer accounts, 66 impersonated brands — means the affected extensions spanned enough of the market that spotting the bad ones by name isn’t reliable. Verify by publisher, not by recognizing the brand name on the icon.
Chrome’s built-in Safety Check (chrome://settings/safetyCheck) will flag extensions Google has since removed from the Web Store, but it only catches post-removal cases. Manual review for anything still live at the time of your audit is required.
For broader supply-chain and extension-ecosystem coverage: /topics/supply-chain/. For ongoing browser vulnerability tracking: /topics/browser/.
Found this useful? Share it.


