737 fake Chrome VPN extensions exposed in proxy-routing campaign

Vlad CONSTANTINESCU

August 13, 2026

737 fake Chrome VPN extensions exposed in proxy-routing campaign

Hundreds of Chrome extensions posing as VPN and privacy tools were linked to a coordinated operation that redirected browser traffic through shared SOCKS5 proxy infrastructure. Some also impersonated established security brands and advertised premium servers that didn’t actually exist.

Key takeaways

  • Socket linked 737 Chrome VPN and proxy extensions to the campaign, which collectively accumulated 75,486 installs
  • Researchers found 274 extensions impersonating 66 established VPN and privacy brands
  • Of 522 packages used for code-level analysis, 520 routed browser traffic through SOCKS5 proxies on port 1082
  • Chrome users who installed an affected extension should remove it and verify that their browser proxy settings have returned to normal

The scale of the operation turns a familiar browser convenience into a supply-chain problem. Users were not tricked into installing an obviously unrelated tool; many downloaded extensions were presented as privacy products, some borrowing the identities of services they may already have known and trusted.

Fake VPN extensions put browser traffic in the middle

Security researchers at Socket uncovered a sprawling Chrome Web Store campaign targeting mainly Russian-speaking users looking to access blocked services. The extensions appeared under numerous names and developer accounts, but shared infrastructure and technical patterns tied them to a single operation.

Once connected, most of the extensions analyzed configured Chrome to send browser requests through SOCKS5 relays controlled by the operator. Socket stressed that proxying itself is not proof of malicious behavior; legitimate browser VPN tools use similar mechanisms. The concern lies in the surrounding deception, including brand impersonation, misleading privacy claims and hidden infrastructure.

Brand impersonation and store evasion amplified the risk

The campaign copied names or branding associated with services including Proton VPN, NordVPN, Surfshark, ExpressVPN and Cloudflare’s 1.1.1.1. Researchers also found premium locations advertised in Japan, Singapore, Canada, Australia and Turkey whose tested hostnames did not resolve.

Researchers identified further signs of deliberate evasion. Forty-nine extensions across 18 publisher accounts received post-approval code changes, while several packages contained nearly identical statements submitted to reviewers claiming no external data transmission or tracking. At the time of the discovery, 221 extensions had been removed and 516 were still listed as active.

What Chrome users should do now

Anyone who installed a VPN extension linked to the campaign should remove it immediately and check Chrome’s proxy settings. Socket also recommends changing credentials entered on non-HTTPS websites while an affected extension was connected and treating browsing activity from that period as potentially visible to a third party.

More broadly, users should verify that a VPN extension is published by the company it claims to represent rather than trust a familiar logo or name. Where possible, download privacy and security software through the vendor’s official website and review browser permissions before installation.

The importance of trustworthy VPNs

Protect your traffic with software from a trusted source. If you need a VPN, Bitdefender Premium VPN provides a dedicated VPN service available directly from Bitdefender. Users looking for broader protection can opt for Bitdefender Ultimate Security, which combines Premium VPN with security for devices and online activity.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader