
Hundreds of Chrome extensions posing as VPN and privacy tools were linked to a coordinated operation that redirected browser traffic through shared SOCKS5 proxy infrastructure. Some also impersonated established security brands and advertised premium servers that didn’t actually exist.
The scale of the operation turns a familiar browser convenience into a supply-chain problem. Users were not tricked into installing an obviously unrelated tool; many downloaded extensions were presented as privacy products, some borrowing the identities of services they may already have known and trusted.
Security researchers at Socket uncovered a sprawling Chrome Web Store campaign targeting mainly Russian-speaking users looking to access blocked services. The extensions appeared under numerous names and developer accounts, but shared infrastructure and technical patterns tied them to a single operation.
Once connected, most of the extensions analyzed configured Chrome to send browser requests through SOCKS5 relays controlled by the operator. Socket stressed that proxying itself is not proof of malicious behavior; legitimate browser VPN tools use similar mechanisms. The concern lies in the surrounding deception, including brand impersonation, misleading privacy claims and hidden infrastructure.
The campaign copied names or branding associated with services including Proton VPN, NordVPN, Surfshark, ExpressVPN and Cloudflare’s 1.1.1.1. Researchers also found premium locations advertised in Japan, Singapore, Canada, Australia and Turkey whose tested hostnames did not resolve.
Researchers identified further signs of deliberate evasion. Forty-nine extensions across 18 publisher accounts received post-approval code changes, while several packages contained nearly identical statements submitted to reviewers claiming no external data transmission or tracking. At the time of the discovery, 221 extensions had been removed and 516 were still listed as active.
Anyone who installed a VPN extension linked to the campaign should remove it immediately and check Chrome’s proxy settings. Socket also recommends changing credentials entered on non-HTTPS websites while an affected extension was connected and treating browsing activity from that period as potentially visible to a third party.
More broadly, users should verify that a VPN extension is published by the company it claims to represent rather than trust a familiar logo or name. Where possible, download privacy and security software through the vendor’s official website and review browser permissions before installation.
Protect your traffic with software from a trusted source. If you need a VPN, Bitdefender Premium VPN provides a dedicated VPN service available directly from Bitdefender. Users looking for broader protection can opt for Bitdefender Ultimate Security, which combines Premium VPN with security for devices and online activity.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts