Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Over 700 Chrome VPN Extensions Found Using Same Proxy Network to Route User Traffic

Over 700 Chrome VPN Extensions Found Using Same Proxy Network to Route User Traffic

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 14, 2026

Human Written
Over 700 Chrome VPN Extensions Found Using Same Proxy Network to Route User Traffic
  • Researchers found 737 Chrome VPN and proxy extensions linked to the same proxy network.

  • The extensions had 75,486 installs, with 274 copying 66 known VPN and privacy brands.

  • Most extensions routed full browser sessions through SOCKS5 servers controlled by one provider.

A large group of 737 Chrome extensions has been found routing browser traffic through proxy servers. The extensions mainly targeted Russian-speaking users seeking access to blocked online services. 

Researchers said the extensions had collected 75,486 installs across at least 40 developer accounts. They also found 274 extensions copying 66 known VPN and privacy brands.

The copied names included Proton VPN, NordVPN, AdGuard VPN, Surfshark, Browsec, and ExpressVPN. Other copied brands included Windscribe, CyberGhost, TunnelBear, 1.1.1.1, and Google’s Outline.

737 Extensions Routed Browser Traffic Through Proxies

Security researcher Kush Pandya said the extensions routed complete browser sessions through SOCKS5 proxy servers. He said 520 of 522 extensions in the main group used the same SOCKS5 network. Most of the extensions changed a Chrome setting called chrome.proxy.settings.

They directed browser traffic to a fixed SOCKS5 server using port 1082. That setup could place the operator between the user and the websites they visit. It could expose browser destinations, source IP addresses, and TLS SNI information.

It could also expose request content when a connection sends information through plain HTTP. Every extension using the proxy also included a bypass list. That list only covered local addresses, including localhost and 127.0.0.1.

As a result, other browser requests went through the SOCKS5 relay. Researchers also found several warning signs within the extensions. Some advertised paid features or premium locations that did not exist.

Others used methods designed to avoid DNS-over-HTTPS blocklists. Some extensions also failed every connection attempt while displaying a fake VPN interface. The fake interface still showed connection animations and status indicators.

Researchers also found an internal manual named “Промт для сотрудников,” meaning “Prompt for employees.” The manual reportedly told workers not to place the proxy domain directly into chrome.proxy.settings. Instead, it instructed them to use the resolved IP address.

It also told workers not to reuse a domain from another extension without separate instructions. Researchers found comments suggesting efforts to avoid Chrome Web Store rules. The extensions also added a remote configuration layer after receiving approval.

Some submissions reportedly used identical explanations during the store review process. Those explanations claimed that no data went to outside servers. They also claimed that the extensions did not track or log users.

Pandya said every affected user sent requests through a server controlled by the threat actor. However, the extension code could not show who owned those proxy servers. He said the operator might own the servers or resell capacity from another provider. If another provider supplied the servers, that party could also occupy the same position.

Chrome Removes 221 Extensions as 516 Remain Active

Researchers said Chrome removed 221 of the extensions from its Web Store. They also said 516 extensions remained listed as active. The threat actor was reportedly linked to a subscription VPN business in Russia.

Researchers based that connection on a 12-digit taxpayer number. They also found Windows build paths inside some extensions. Those paths contained Russian-language folder names and product-related files.

Researchers said the main issue was not simply the use of VPN or proxy technology. Legitimate VPN services can also route browser traffic through proxy servers. The key concern was the alleged use of well-known brands to disguise the extensions.

Google is actively working on new Chrome protections to address similar extension abuse. The company plans to block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged personal devices, a tactic frequently used by malware to force-install unwanted extensions and lock users out of removal.

Researchers also pointed to fake premium servers and hidden proxy settings. They identified false statements made during store reviews as another warning sign. They also found code changes made after some extensions received approval.

According to the researchers, the packages and public infrastructure establish several points. These include brand impersonation, hidden proxy settings, fake premium servers, and misleading review claims. They also identified code replacement after approval as part of the activity.

The report did not establish whether the threat actor directly owned every proxy server. It also did not establish whether the operator used another provider for some server capacity.

Removed Chrome Extension Returns With New Monetization Code

The findings came alongside a separate report about a Chrome extension called “AI Sidebar with Deepseek, ChatGPT, Claude, and more.” Netskope Threat Labs said Chrome had previously removed the extension for prompt poaching activity. The extension later returned through a clean-then-poisoned update sequence.

The changes appeared in versions 1.7.2.0 and 1.7.3.0. The updates moved through Google’s CRX content delivery network on July 31, 2026. Netskope said the newer version contained a 21-line addition linked to monetization. The added code focused on extension update and uninstall events.

The company said the extension first released a harmless update. That update removed the earlier data theft code and admitted the wrongdoing. Netskope then said the extension returned with another update about two weeks later.

The new version no longer contained the conversation-stealing code. Instead, the company found code that opened an affiliate link in a visible browser tab. The action happened whenever users updated or removed the extension.

Netskope also said the code stopped DeepSeek users from being redirected to ChatGPT. Both findings involve Chrome extensions that researchers examined for suspicious behavior. The reports highlight different activities involving browser extensions and their code.

The information about the 737 extensions comes from the research described by The Hacker News. The separate extension findings come from Netskope Threat Labs, as reported in the supplied material.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.