Fake Chrome VPN extensions hijack traffic: 737 malicious add-ons identified
Researchers found 737 fake VPN extensions on Chrome Web Store, impersonating top VPN brands, with 75,000 installs, all traced to one operator.
The findings come from the team's investigation, which identified the extensions across at least 40 Chrome Web Store developer accounts. More than 270 of the add-ons impersonate 66 well-known VPN services and privacy brands. Combined, they have amassed more than 75,000 installs, mostly among Russian-speaking users seeking ways to access blocked services.
The researchers traced the operation to a single Russian VPN subscription business trading as Myxa VPN. They connected the extensions using a shared analytics account, clustered domain registrations, common hosting, and leaked Windows build paths that pointed to the same project folder. The free extensions appear to act as a funnel, pushing users toward a paid subscription.
Socket said some of the paid promises were fictional. When it tested 200 premium hostnames across 40 domains, none returned an A record, meaning the advertised servers in countries such as Japan, Singapore, and Australia did not actually exist.
The core technique is consistent across nearly every extension. Once a user presses Connect, all browsing traffic is routed through a server controlled by the operator, with no per-site exceptions. The tool adds no encryption, so it does not provide the protective function of a real VPN. Worse, 104 extensions resolved their proxy addresses through Cloudflare or Google DNS-over-HTTPS and handed Chrome a raw IP address, a method that makes the operator's servers harder to block or detect.
This setup gives the operator a clear view of user activity, including the websites visited, TLS SNI metadata, the user's source IP address, and any data sent over unencrypted HTTP. Any information typed into a non-HTTPS page, including login credentials, could be exposed. Socket said it does not know whether data has actually been collected or misused, but the capability itself is a serious concern.
Google has already acted against the extensions, but not completely. By the time Socket collected its data, 221 of the 737 extensions had been removed, while 516 remained listed. Socket advises anyone who believes they installed one of these fake extensions to remove it immediately, check that Chrome's proxy configuration has returned to normal, and change any credentials entered on non-HTTPS websites while the extension was active. Users can review their proxy settings by going to browser settings and searching for "proxy."