Hundreds of Fake Chrome VPN Extensions Routed User Traffic Through SOCKS5 Proxies
More than 737 browser extensions published in the Chrome Web Store impersonated popular VPN and proxy services while routing users’ internet traffic through SOCKS5 proxies controlled by a single provider.
The malicious Chrome extensions copied the branding of well-known services, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public DNS resolver.
Researchers at application security company Socket said the campaign was operated through at least 40 publisher accounts that shared analytics accounts and other infrastructure.
The extensions were downloaded nearly 75,000 times from the Chrome Web Store. Most downloads came from Russian users searching for VPN tools to bypass services blocked in the country.
According to Socket, the extensions forced browser traffic through attacker-controlled relay servers. This exposed the websites users visited, TLS Server Name Indication (SNI) values, source IP addresses, and any data sent over unencrypted HTTP connections. Socket researchers described the campaign.
Researchers identified three main behaviors associated with the fake Chrome VPN extensions:
- 520 extensions configured Chrome to route browser traffic through a SOCKS5 proxy operated by the campaign on port 1082.
- 104 extensions resolved proxy hostnames through Cloudflare or Google DNS-over-HTTPS, helping conceal the operators’ domains from monitoring and analysis.
- Some extensions promoted non-existent premium servers in Japan, Singapore, Canada, Australia, and Türkiye as part of a subscription scam.
By the time Socket collected the extensions, Google had already removed 212 of them. As a result, researchers could not analyze the code associated with every extension linked to the campaign.
Strings discovered in the available extensions indicate that the operation may have been designed to direct users toward a Russian subscription-based VPN service.
Socket said the technical mechanisms used by the extensions did not always differ from those found in legitimate VPN software. However, researchers identified multiple signs of deliberate deception, including:
- Impersonating well-known VPN and proxy brands.
- Advertising premium server locations that did not exist.
- Using payment or connection features that failed to work as advertised.
- Providing misleading disclosures to Chrome Web Store reviewers.
- Adding remote configuration capabilities after the extensions were approved.
- Using techniques designed to hide proxy destinations from security analysis.
Socket said Google had removed more than 200 extensions associated with the campaign, but over 500 potentially related extensions remained available in the Chrome Web Store at the time of the researchers’ report.
Socket published the IDs of the extensions linked to the campaign and advised users to check Chrome for suspicious VPN or proxy add-ons. If any are installed, users should remove them immediately and verify that Chrome’s proxy settings have returned to their normal configuration.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




