Security researchers have uncovered a coordinated campaign involving 31 malicious Chrome extensions masquerading as VPNs. These extensions—surveyed in early September 2026—redirect browser traffic through proxy servers controlled by the attackers. Despite offering services tied to popular platforms, they pose serious privacy and security risks.
How the Attack Works
The extensions, all Russian-language and claiming to offer VPN protection for services like RuTracker, YouTube, Telegram, Instagram, ChatGPT, Netflix, Gemini, Discord, Spotify, LinkedIn, and others, request full browser proxy permissions through Chrome’s APIs. Once granted host access across all URLs, they install proxy auto-configuration (PAC) scripts. These scripts decide whether a given URL is routed directly or through the proxy—however, the destination servers aren’t hardcoded. Instead, the list of proxy targets is pulled dynamically from external sources without needing an extension update.
The configuration servers include GitHub Pages, Blogspot, a Google document, and a Telegram channel. To disguise this setup, operators obfuscate the server lists using Base64 with a Caesar shift—lightweight encryption that may confuse cursory inspections but offers minimal actual protection. The attackers also embed shared credentials that expire monthly. For those seeking more features or fewer restrictions, a paid “VIP” tier costs 299 roubles and is available through specific APIs.
Risk, Scale & Exposure
This campaign gained a large install base quickly, totaling around 356,000 users. One of the extensions, RuTracker VPN, accounts for roughly 200,000 of those installations alone. The rest are spread across the other 30 variants, all built on the same underlying code. In the case of one variant called “Total VPN,” nearly all browser traffic is routed through the proxy network—vastly increasing exposure compared to extensions that only proxy specific sites tied to promoted services.
Routing through unknown infrastructure allows operators to observe metadata such as destinations and connection patterns. If content isn’t encrypted—say via HTTP—attackers could also intercept, modify, or inject content. Even with HTTPS, users remain vulnerable to metadata tracking, potential redirections, or worse if trust protections are bypassed.
Detection, Response & Best Practices
Researchers conducted reverse engineering of 28 of the 31 extension packages and published SHA-256 hashes for each so that detection tools can more easily spot the malicious variants. They also identified overlapping domain names used by the proxy infrastructure—names like de8.staticvaultcdn.org, de4.servefaststatic.work, and de34.rapidstaticserve.cc—that appear connected to known VPN services like Browsec. Whether these associations indicate direct ownership remains unconfirmed but are flagged as serious leads.
Users are urged to uninstall any of the listed extensions immediately, reboot their browser, check proxy settings at both the browser and OS levels for unauthorized entries, and change passwords for accounts possibly accessed during the exposure period. Revoking active sessions and keeping an eye out for unusual logins also help.
For institutions and enterprise defenders, it’s critical to block the identified extension IDs, configuration domains, and subscription API hosts. Checking outbound connections to URLs like s-extension.github.io, dtxtension.blogspot.com, t.me/liservers, api.hhos.ru, and mainapi for suspicious activity should be part of routine monitoring. Matching archived hashes against managed endpoints adds another layer of defense.
The core takeaway is simple: any extension that claims to act as a single-site or service-specific VPN yet demands permission to access all URLs and pulls routing rules from external sources poses an unacceptable level of risk.
Understanding this trend is vital. While browser-based VPNs promise convenience, many users may not realize how much control they hand over. As more extensions drop into the Chrome Web Store with vague promises and unrestricted permissions, vigilance becomes the first line of defense. Going forward, we need better transparency in extension behavior, stricter vetting from browser vendors, and smarter user education around permissions.