Hundreds of Fake Chrome VPN Extensions Hijack User Traffic

Recent investigations have uncovered a significant operation involving 737 Chrome extensions falsely advertised as free VPN or proxy tools. These extensions, instead of providing the promised privacy and access to restricted services, rerouted user browser sessions through SOCKS5 proxy servers controlled by the operators, potentially exposing sensitive user data.

The scale of this operation is alarming. Researchers identified these extensions across at least 40 developer accounts on the Chrome Web Store, amassing over 75,000 installations. A substantial number of these extensions targeted Russian-speaking users seeking access to blocked websites and services.

Analysts at Socket.dev conducted a thorough examination of hundreds of extension packages and store listings, revealing that 274 of these extensions mimicked the names or branding of 66 established VPN and privacy services. This tactic was likely employed to deceive users into believing they were installing legitimate tools.

While the research does not conclusively state that all routed data was collected or misused, it confirms that the operators had the capability to monitor browser traffic whenever an extension was active. This exposure includes visited destinations, connection metadata, and the user’s source IP address. Notably, plain HTTP requests could reveal their full contents to the proxy operator.

Technical Insights into the Malicious Extensions

Of the 522 retrieved extension packages, 520 were configured to direct Chrome to use a fixed SOCKS5 server on port 1082. Their bypass rules were limited to local addresses, meaning that all other browser traffic was routed through the designated proxy upon user activation. This setup granted the proxy operator visibility into the user’s browsing activities.

In 104 instances, the extensions resolved proxy hosts through encrypted DNS services before supplying Chrome with a raw address. This method reduces the visibility of standard domain lookups, further obscuring the malicious activity.

Additionally, 66 extensions utilized remote configuration. This feature allowed the extensions to follow web redirects, locate new infrastructure domains, and download updated settings without requiring an extension update. Such behavior underscores the potential for an approved extension to alter its risk profile post-installation.

Deceptive Practices and User Protection

These extensions often requested only the proxy permission, which might appear innocuous to casual users. However, this permission enables control over where browser traffic is directed. The extensions employed various deceptive practices, including:

  • Impersonating reputable VPN brands to gain user trust.
  • Promising premium server locations that did not resolve.
  • Displaying misleading reviews claiming no data was transmitted to external servers, despite evidence to the contrary.

Investigators discovered 200 advertised premium server names across 40 domains that returned no address records. Some extensions displayed polished connection interfaces but were coded to fail every connection attempt, further misleading users.

At the time of data collection, Google had removed 221 of these extensions from the Chrome Web Store. However, 516 remained listed, highlighting the persistence and adaptability of such malicious campaigns.

This incident underscores the critical need for users to exercise caution when installing browser extensions, especially those promising enhanced privacy or access to restricted content. Verifying the legitimacy of extensions, scrutinizing permissions, and staying informed about potential threats are essential steps in safeguarding personal data and maintaining online security.