LIVE · cybersecurity feed
Live wire
security

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]

zeroday.news ·

More than 737 browser extensions, many impersonating well-known VPN and proxy services, were found on the Chrome Web Store routing user traffic through SOCKS5 proxies. The campaign, identified by researchers at application security company Socket, involved 40 publisher accounts and a shared analytics account, with extensions downloaded nearly 75,000 times, predominantly by users in Russia.

The extensions mimicked established brands such as Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare's 1.1.1.1 public DNS resolver. By forcing all browser traffic through their relays, the operators of these proxies could potentially observe every destination, TLS SNI value, the victim's source IP address, and any unencrypted HTTP request body.

Socket's analysis revealed three primary malicious behaviors: 520 extensions were configured to route all browser traffic through the operator's SOCKS5 proxies on port 1082; 104 extensions resolved their proxy hostnames using Cloudflare or Google DNS-over-HTTPS to obscure the operator's domain; and some extensions advertised non-existent premium servers in locations like Japan, Singapore, Canada, Australia, and Turkey, suggesting subscription fraud.

While 212 of the extensions had already been removed when Socket collected them, preventing full code analysis, the remaining evidence points to an effort to funnel users into a subscription-based VPN service in Russia. The mechanism itself resembled legitimate services, but researchers noted several indicators of intentional deception.

These deceptive tactics included the impersonation of well-known brands, the advertisement of non-existent premium server locations, non-functional payment or connection mechanisms, misleading disclosures to store reviewers, and the addition of remote configuration capabilities after initial approval. The operators also employed techniques to hide proxy destinations from analysis.

Google has confirmed the removal of over 200 extensions associated with this campaign. However, Socket reported that more than 500 of the identified extensions remained available on the Chrome Web Store at the time of their report.

Users are advised to review their installed Chrome extensions for any of the IDs published by Socket and remove them if found. It is also recommended to verify that Chrome's proxy configuration has reverted to its normal settings after removing any suspicious extensions.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]