A massive campaign involving 737 free VPN and proxy browser extensions has been uncovered, with the majority apparently targeting Russian-speaking users looking to bypass blocked services. Researchers say the extensions were designed to route users’ browser traffic through a proxy infrastructure controlled by a single provider, potentially exposing sensitive browsing information.
According to security research firm Socket, the extensions were distributed through at least 40 Chrome Web Store developer accounts and collectively recorded 75,486 installs.
Of the extensions analyzed, 274 were found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare’s 1.1.1.1, and Google’s Outline.
Hidden SOCKS5 Proxy Configuration
Socket security researcher Kush Pandya said the extensions were presented as censorship-circumvention tools but routed users’ browser sessions through SOCKS5 proxies operated by the same infrastructure.
“520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure,” Pandya said.
The majority of the extensions reportedly configure Chrome’s chrome.proxy.settings API to send browser traffic through a fixed SOCKS5 server operating on port 1082.
This configuration could place the operator in an adversary-in-the-middle (AitM) position. Depending on the type of traffic and encryption involved, the operator could potentially observe browser destinations, source IP addresses, TLS SNI information, and request bodies transmitted over unencrypted HTTP.
The extensions also reportedly include a proxy bypass list containing only loopback addresses such as localhost and 127.0.0.1. As a result, virtually all other browser requests are directed through the SOCKS5 relay once the extension is connected.
Hundreds of Extensions Still Active
Of the 737 extensions identified, 221 have been removed from the Chrome Web Store, while 516 were still listed as active at the time of the investigation.
Researchers also found indications that the operation may be connected to a subscription VPN business operating in Russia. Clues reportedly include a 12-digit taxpayer identification number and Windows build paths embedded in some extensions.
Some of those paths reportedly reference directories containing Russian-language folder names and project files associated with the extensions.
While the underlying proxy functionality is not inherently different from what a legitimate VPN or proxy service might provide, researchers say the major concern is the deliberate impersonation of established VPN brands and the lack of transparency surrounding the proxy infrastructure.
Red Flags Found in the Extensions
Researchers identified several additional warning signs across the extension packages, including:
- Claims of paid tiers or premium server locations that do not actually exist.
- Attempts to evade DNS-over-HTTPS blocklists.
- Extensions that fail connection attempts while displaying a convincing fake interface, including connection animations and status indicators.
- Internal documentation instructing developers to avoid placing proxy domains directly into
chrome.proxy.settingsand instead use resolved IP addresses. - Instructions warning developers not to reuse domains from other extensions without authorization.
- Comments suggesting deliberate efforts to circumvent Chrome Web Store policies.
- The introduction of a remote-configuration mechanism after extensions had already been approved.
- Attempts to influence the Chrome Web Store review process using identical declarations that claimed no data was transmitted to external servers and that there was no user tracking or logging.
According to Pandya, the practical risk is that every user connected to one of the affected extensions could have their browser requests routed through infrastructure controlled by the threat actor or another upstream provider.
“For each affected user, while the extension is connected, every request passes through a server the threat actor controls,” Pandya said.
Researchers noted that the available code does not conclusively establish whether the operator owns the proxy servers or is simply reselling capacity from another provider.
However, the investigation did establish several other findings, including brand impersonation, undisclosed proxy configurations, nonexistent premium servers, misleading statements submitted to store reviewers, and post-approval code changes.
Previously Removed Chrome Extension Returns With New Monetization Scheme
The findings come as Netskope Threat Labs reported the return of another problematic Chrome extension, “AI Sidebar with Deepseek, ChatGPT, Claude, and more.”
The extension had previously been removed after researchers discovered it was involved in prompt-poaching activity.
According to Netskope, the extension later returned to the Chrome Web Store and underwent another suspicious update sequence on July 31, 2026.
The changes were delivered through Google’s CRX content delivery network and involved versions 1.7.2.0 and 1.7.3.0.
Researchers described the latest change as a “clean-then-poisoned” update sequence. The extension initially released an update that removed its earlier data-theft functionality and acknowledged the wrongdoing. Roughly two weeks later, another update introduced a new monetization mechanism.
New Update and Uninstall Monetization
Netskope said the new functionality consisted of a small, 21-line addition that monitored extension update and uninstall events.
The extension reportedly opens an affiliate link in a foreground browser tab whenever the extension is updated or uninstalled.
The latest version also reportedly suppresses the normal redirection of DeepSeek users to ChatGPT.
Netskope said the extension no longer contains the conversation-exfiltration code previously identified by researchers, but the new monetization behavior demonstrates that removing malicious functionality does not necessarily mean an extension has become trustworthy.
What Users Should Do
The latest discoveries highlight the risks of installing browser extensions solely because they promise free VPN access, AI tools, privacy features, or access to blocked websites.
Users should be particularly cautious of extensions that:
- Impersonate well-known VPN or privacy brands.
- Have very few reviews or an unusually large number of similarly named extensions.
- Request broad browser permissions without a clear reason.
- Claim to provide premium VPN servers for free.
- Behave differently after an update.
- Come from unfamiliar developers or newly created publisher accounts.
A browser extension can potentially see or influence a significant portion of a user’s web activity depending on the permissions and APIs it uses. For VPN and proxy extensions in particular, users should verify the developer, privacy policy, infrastructure, and reputation of the service before routing browser traffic through it.
The campaign also demonstrates why users should not assume that an extension available through an official browser marketplace is automatically safe. Malicious or deceptive extensions can sometimes pass initial review and later receive updates that introduce new functionality.
For users who rely on VPN extensions to bypass censorship or protect their privacy, choosing a reputable provider with transparent ownership, established security practices, and a verifiable privacy policy is considerably safer than installing an unfamiliar extension simply because it promises free access.
