VMTech
Discuss a project

Hundreds of Chrome VPN Extensions Used Undisclosed SOCKS5 Proxies

Hundreds of Chrome VPN Extensions Used Undisclosed SOCKS5 Proxies

Security researchers have identified 737 free Chrome VPN and proxy extensions that routed browser traffic through proxy infrastructure controlled by a single provider. The extensions, distributed through at least 40 Chrome Web Store developer accounts, accumulated 75,486 installs and primarily targeted Russian-speaking users seeking access to blocked services.

Socket found that 274 of the extensions impersonated 66 recognised VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare’s 1.1.1.1 and Google’s Outline. Google had removed 221 of the identified add-ons at the time of the research, while 516 were still listed as active.

Browser sessions sent to a fixed proxy

The central technical finding is that the add-ons configured chrome.proxy.settings to send users’ entire browser sessions to a fixed SOCKS5 server on port 1082. Researcher Kush Pandya said 520 of 522 extensions in the bulk corpus used the same SOCKS5 infrastructure.

Each extension that configured a proxy included a bypass list limited to loopback addresses such as localhost and 127.0.0.1. As a result, every other browser request was directed through the SOCKS5 relay after a user connected to the purported VPN service.

This placed the operator in an adversary-in-the-middle position. The proxy could observe browser destinations, source IP addresses, TLS SNI values and request bodies sent over plain HTTP. The code does not establish whether the threat actor owned the proxy servers or resold upstream capacity, but either arrangement leaves another party able to view traffic flowing through the relay.

Impersonation and review-evasion indicators

VPN and proxy routing are not inherently malicious: legitimate services use comparable mechanisms. The researchers distinguished this cluster by its impersonation of established brands and by undisclosed proxy settings. The packages also advertised paid tiers or premium locations that did not exist, and some failed connection attempts while displaying a convincing interface with connection animations and status indicators.

Other indicators included DNS-over-HTTPS blocklist evasion, comments suggesting attempts to evade Chrome Web Store policies, and a remote-configuration layer introduced after approval. An internal manual instructed staff not to place a domain directly in chrome.proxy.settings, to use a resolved IP address instead, and not to reuse a domain from another extension without separate instructions.

The investigation also found identical statements submitted during store review, including claims that no data was transmitted to external servers and that there was no user tracking or logging. The campaign follows a wider pattern of browser-extension risk, including Chrome security issues documented in Chrome security issues documented in that underline the importance of controlling browser software in business environments.

A separate extension returned with a new payload

Netskope Threat Labs separately reported that “AI Sidebar with Deepseek, ChatGPT, Claude, and more” returned after an earlier removal related to Prompt Poaching. A benign version 1.7.2.0 update removed the data-theft code, but version 1.7.3.0, delivered through Google’s CRX content delivery network on July 31, 2026, added 21 lines of monetisation code.

That payload opened an affiliate link in a foreground tab whenever the extension updated or was uninstalled, and it suppressed redirection of DeepSeek users to ChatGPT. For businesses, the practical response is to inventory installed browser extensions, remove unverified VPN and proxy tools, and restrict approved extensions to products that have been independently vetted.

#chromesecurity#vpnsecurity#browserprivacy#extensionrisk
Open analytics
On the site 0 views
min read 4 12.08.2026
Instagram

Hundreds of Chrome VPN Extensions Used Undisclosed SOCKS5 Proxies

Open the post on Instagram ↗