More than 737 browser extensions, many impersonating well-known VPN and proxy services, were found on the Chrome Web Store routing user traffic through SOCKS5 proxies. The campaign, identified by researchers at application security company Socket, involved 40 publisher accounts and a shared analytics account, with extensions downloaded nearly 75,000 times, predominantly by users in Russia.
The extensions mimicked established brands such as Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare's 1.1.1.1 public DNS resolver. By forcing all browser traffic through their relays, the operators of these proxies could potentially observe every destination, TLS SNI value, the victim's source IP address, and any unencrypted HTTP request body.
Socket's analysis revealed three primary malicious behaviors: 520 extensions were configured to route all browser traffic through the operator's SOCKS5 proxies on port 1082; 104 extensions resolved their proxy hostnames using Cloudflare or Google DNS-over-HTTPS to obscure the operator's domain; and some extensions advertised non-existent premium servers in locations like Japan, Singapore, Canada, Australia, and Turkey, suggesting subscription fraud.
While 212 of the extensions had already been removed when Socket collected them, preventing full code analysis, the remaining evidence points to an effort to funnel users into a subscription-based VPN service in Russia. The mechanism itself resembled legitimate services, but researchers noted several indicators of intentional deception.
These deceptive tactics included the impersonation of well-known brands, the advertisement of non-existent premium server locations, non-functional payment or connection mechanisms, misleading disclosures to store reviewers, and the addition of remote configuration capabilities after initial approval. The operators also employed techniques to hide proxy destinations from analysis.
Google has confirmed the removal of over 200 extensions associated with this campaign. However, Socket reported that more than 500 of the identified extensions remained available on the Chrome Web Store at the time of their report.
Users are advised to review their installed Chrome extensions for any of the IDs published by Socket and remove them if found. It is also recommended to verify that Chrome's proxy configuration has reverted to its normal settings after removing any suspicious extensions.






