Over 737 malicious Chrome extensions have been discovered impersonating top-tier VPN services like NordVPN and ExpressVPN. These extensions route user traffic through rogue proxies, putting sensitive data at extreme risk.

Key Takeaways

  • 737+ fraudulent extensions found on the Chrome Web Store.
  • Major brands like NordVPN and Cloudflare were impersonated.
  • Nearly 75,000 downloads recorded, primarily targeting Russian users.
  • Attackers can access source IPs and destination data via SOCKS5 proxies.

A massive cybersecurity campaign has been uncovered involving more than 737 browser extensions published on the Chrome Web Store. These malicious tools were designed to impersonate well-known, trusted VPN and proxy services, including Proton VPN, NordVPN, Surfshark, and ExpressVPN.

According to researchers at application security firm Socket, these extensions were not mere glitches but a coordinated effort using 40 different publisher accounts. The campaign has already reached nearly 75,000 downloads, largely targeting users in Russia seeking to bypass regional internet restrictions.

Why This Matters

BozokMedia analysis shows that the technical mechanism used by these attackers is devastatingly effective. By forcing all browser traffic through a controlled relay, the threat actor's server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP. This essentially gives attackers a 'man-in-the-middle' vantage point over your entire browsing session.

Once attackers gain valid access or credentials, traditional prevention measures see a sharp decline in effectiveness.

Malicious Tactics Uncovered

The research identified three distinct patterns of behavior used by the attackers to maintain control and evade detection:

  • Traffic Hijacking: 520 extensions were configured to route all traffic through SOCKS5 proxies on port 1082.
  • DNS Obfuscation: 104 extensions used Cloudflare or Google DNS-over-HTTPS to hide their proxy hostnames from scrutiny.
  • Subscription Fraud: Many extensions advertised non-existent premium servers in locations like Japan, Singapore, and Canada to trick users into paying for fake services.
Did You Know?: Many of these extensions were designed to add remote configurations *after* they had already passed Google's initial approval process.

Frequently Asked Questions

1. Are my passwords safe if I use these extensions?

Not necessarily. While modern encryption (HTTPS) protects much of your data, attackers can still see where you are going and capture data sent over unencrypted connections.

2. How can I secure my browser?

Audit your installed extensions immediately. Remove anything you don't recognize and ensure your Chrome proxy settings are set to 'No proxy' or 'Auto-detect'.