Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Alert: Malicious VPN Extensions Compromise Chrome

Security Alert: Malicious VPN Extensions Compromise Chrome

Posted on September 29, 2026 By CWS

A large-scale operation involving 31 Chrome extensions, predominantly in Russian, has been discovered. These extensions masquerade as ‘VPN for X’ tools while secretly rerouting browser traffic through hidden proxy servers. The campaign, revealed by Risky Plugins on September 19, 2026, remains active and has amassed approximately 356,000 installations.

Widespread Installation and Targeted Platforms

These deceptive extensions aim to attract users looking for access to restricted services. They bear names associated with popular platforms such as RuTracker, YouTube, Telegram, and others, thus misleading users. Analysts have linked these extensions to three publisher accounts, uncovering a shared codebase across all 31. Remarkably, the RuTracker VPN alone has garnered around 200,000 installations.

The extensions exploit Chrome’s proxy API capabilities, requesting powerful permissions to modify browser proxy settings and intercept web requests. This enables them to direct user traffic through a Proxy Auto-Configuration (PAC) script that defines whether URLs connect directly or via a proxy. The proxy list is dynamically updated from external sources, bypassing the need for extension updates.

Technical Analysis and Potential Risks

Research conducted in early September highlighted that the extensions’ PAC scripts are downloaded from various online platforms, including GitHub Pages and Blogspot. Although the proxy server list is obscured using a simple Caesar shift over Base64, it does not provide substantial cryptographic security. The decoded data involves shared proxy credentials that renew monthly, and a VIP service priced at 299 roubles is available through specified APIs.

While most extensions proxy specific service-related traffic, the ‘Total VPN’ variant routes all browser traffic, heightening user exposure. This allows proxy operators to observe metadata and potentially manipulate unencrypted HTTP content. Although HTTPS encrypts content, routing traffic through untrusted proxies increases the risk of monitoring and manipulation.

Recommended Actions for Users and Enterprises

Risky Plugins have archived and analyzed the CRX packages for 28 of the extensions, publishing SHA-256 hashes for detection purposes. They identified fallback hostnames linked to known premium servers, treating these as potential leads for further investigation.

Users are advised to immediately uninstall any suspicious extensions, restart their browsers, and review proxy settings for anomalies. They should also update credentials for sensitive accounts used during the exposure period and monitor for unusual activity. Enterprises should block the identified extension IDs, investigate outbound connections to specific domains, and use archived hashes to safeguard managed endpoints.

The overarching caution is clear: any VPN extension that requests comprehensive URL access and updates routing instructions post-installation poses a significant trust risk. Users should remain vigilant and prioritize privacy and security practices.

Cyber Security News Tags:browser hijacking, browser security, Chrome extensions, Chrome security, Cybersecurity, fake VPN, internet privacy, internet safety, malicious extensions, Malware, online security, proxy infrastructure, proxy servers, VPN, VPN risks

Post navigation

Previous Post: Fake Jev AI Stores Exploit Users with Costly Access
Next Post: MCP Python SDK Vulnerability Risks OAuth Credential Theft

Related Posts

Russian Officials’ Phones Targeted by Foreign Spyware Russian Officials’ Phones Targeted by Foreign Spyware Cyber Security News
SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE Cyber Security News
CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks Cyber Security News
DoorDash Confirms Data breach – Hackers Accessed Users Personal Data DoorDash Confirms Data breach – Hackers Accessed Users Personal Data Cyber Security News
Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Cyber Security News
Malware Mastermind Andrei Tarasov Evades US Extradition Returns to Russia Malware Mastermind Andrei Tarasov Evades US Extradition Returns to Russia Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Fixes Zero-Day Vulnerability Uncovered by Meta
  • MCP Python SDK Vulnerability Risks OAuth Credential Theft
  • Security Alert: Malicious VPN Extensions Compromise Chrome
  • Fake Jev AI Stores Exploit Users with Costly Access
  • Microsoft SharePoint Vulnerability Heightens Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Fixes Zero-Day Vulnerability Uncovered by Meta
  • MCP Python SDK Vulnerability Risks OAuth Credential Theft
  • Security Alert: Malicious VPN Extensions Compromise Chrome
  • Fake Jev AI Stores Exploit Users with Costly Access
  • Microsoft SharePoint Vulnerability Heightens Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark