737 fake VPN extensions in Chrome: all the traffic went through someone else's proxy
Researchers at Socket have described a campaign of 737 free VPN and proxy extensions in the Chrome Web Store, published from at least 40 developer accounts and installed 75,486 times. Almost all of them do the same thing: they point the browser at a SOCKS5 relay on port 1082 that belongs to the operator, with only local addresses excluded. From that position the operator sees every destination, the server name in each TLS handshake, the user's real address and the full contents of anything still sent over plain HTTP.
Which brands were copied
274 of the extensions impersonate 66 established names. Among them: Proton VPN, NordVPN, Surfshark, ExpressVPN, CyberGhost, Windscribe, TunnelBear, AdGuard VPN, Browsec, Cloudflare's 1.1.1.1 and Google's Outline. Two more matter especially for readers who use a browser to get around blocking: AmneziaVPN, copied by 22 separate extensions, and AntiZapret. These are precisely the tools that audience trusts, which is why they were worth copying.
One live example makes the scale concrete. The extension with the identifier ilbpmeeaifiojjiohfffjmgpgcfcaajg sits in the store as "1.1.1.1 VPN" with Cloudflare's branding lifted wholesale, a thousand installs and a five star rating from eight reviews, and the store shows a prospective user no warning at all.
Why names will not help you
Do not try to check yourself against a list of titles. The same names repeat across dozens of clones, they are edited after publication, and a takedown is followed by a fresh upload under a slightly different one. The stable identifier is the extension ID, the long string of letters in its store address, and Socket published the IDs of all 737.
How to check your browser
Open chrome://extensions, switch on developer mode in the top corner, and each extension will show its ID. Compare those IDs with the list in Socket's report. Then open chrome://settings and search for "proxy" to confirm the browser is not still pointed at someone else's server.
What the operators did to stay in the store
- They asked for one permission that looks harmless for a VPN tool, the ability to set a proxy, and nothing else that would attract attention.
- 104 extensions resolved the proxy host through encrypted DNS at Cloudflare or Google, then handed Chrome a bare address, so the lookup that would normally expose the domain never happened in the clear.
- 66 added a remote configuration layer after approval, which lets the operator change infrastructure without shipping an update the store would review.
- They advertised premium servers in Japan, Singapore, Canada, Australia and Turkey. All 200 of those subdomains resolve to nothing, which makes the paid tier a sale of something that does not exist.
Who is behind it
Socket links the estate to a subscription VPN business operating in Russia under the name Myxa VPN, whose billing dashboard sells the browser extension as a paid tier: the hundreds of free listings are the funnel. The economics explain why removals do not end it. A Chrome Web Store developer account costs five dollars, so a takedown costs the operator the price of a coffee and a new upload. Google has removed 221 of the extensions; 516 were still listed as active when the data was collected, carrying 58,318 of the installs.
A browser extension is not a VPN
This is the part worth carrying away from the story. An extension does not build a tunnel for your machine, it tells the browser to send its requests through a server, which is exactly what these did. Whether that is protection or surveillance depends entirely on who runs the server and what they promise in writing. Traffic from other applications, from the system updater, from a messenger, does not go through it at all, so the padlock in the browser says nothing about the rest of the device.
If you use the browser extension of a service you actually pay for, that is a reasonable convenience. A free extension from an unknown publisher is a stranger offering to carry your post, and the offer is the whole business model.
If you had one of these installed
- Remove the extension and check the proxy setting afterwards, as above.
- Change the passwords you typed on any site that was not using HTTPS while it was connected.
- Treat that period of browsing history as seen by a third party, which matters most if you were reaching services that are blocked where you live.
• 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection - Socket
• Hundreds of fake Chrome VPN extensions route traffic through a proxy - BleepingComputer
• 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies - The Hacker News
• 737 Chrome VPN extensions impersonate brands to hijack browser traffic - CyberInsider