737 Chrome VPN Extensions Caught Stealing User Data in Massive Privacy Breach
A massive campaign involving 737 fraudulent VPN and proxy browser extensions has been uncovered, primarily targeting Russian-speaking users seeking to bypass internet censorship. These extensions, distributed through at least 40 developer accounts on the Chrome Web Store, accumulated over 75,000 installations before being detected. Notably, 274 of these malicious extensions impersonated 66 legitimate VPN brands including major names like NordVPN, Proton VPN, ExpressVPN, and Surfshark. While Google has removed 221 of these extensions, over 500 remain active on the platform at the time of discovery.
The technical mechanism behind this threat is particularly concerning. Rather than providing legitimate VPN services, these extensions route all browser traffic through a single SOCKS5 proxy infrastructure controlled by the threat actor, effectively placing them in an adversary-in-the-middle position. This configuration allows the operators to monitor browser destinations, capture source IP addresses, view TLS Server Name Indication values, and intercept any data transmitted over unencrypted HTTP connections. The extensions use a bypass list containing only loopback addresses, ensuring that virtually all user traffic passes through the attacker's infrastructure once the supposed VPN service is activated.
Evidence suggests the operation is run as a subscription-based VPN business in Russia, based on taxpayer identification numbers and file path information embedded in some extensions. The primary danger lies not in the proxy functionality itself, which may work similarly to legitimate services, but in the deliberate impersonation of trusted brands and the undisclosed routing of user traffic through unknown infrastructure. Security researchers emphasize that users have no way of knowing whether the threat actor owns the proxy servers directly or is reselling capacity from another provider, meaning potentially multiple parties could have access to user traffic.
In related news, a Google Chrome extension called "AI Sidebar with Deepseek, ChatGPT, Claude, and more" has returned to the store months after being removed for malicious behavior. After releasing a clean update that appeared to address previous data-stealing code, the extension betrayed users again two weeks later by introducing monetization code that opens affiliate links during updates or uninstallation events. This pattern of clean-then-poisoned updates demonstrates an evolving threat landscape where malicious developers attempt to rebuild trust before reintroducing harmful functionality.
Stay secure — stay Wavasec. 🔐