A significant security concern has emerged with the identification of 737 free VPN and proxy extensions that are primarily targeting users who speak Russian. These extensions are designed to intercept internet traffic by redirecting it through a proxy network, potentially compromising user privacy. The findings were revealed by cybersecurity researcher Kush Pandya.
Widespread Installation and Brand Impersonation
The malicious extensions have been distributed across approximately 40 developer accounts on the Chrome Web Store, accumulating over 75,000 installations. Notably, 274 of these extensions mimic 66 well-known VPN and privacy service brands, such as Proton VPN, NordVPN, and Surfshark, as reported by security firm Socket.
The extensions route the entire browsing session through SOCKS5 proxies, with 520 out of 522 extensions using the same proxy infrastructure. This setup allows the threat actor to act as an intermediary, observing all browser traffic, source IPs, and TLS SNI values, which raises significant privacy concerns.
Technical Exploits and Privacy Concerns
The operational mechanism involves setting the Chrome browser’s proxy settings to a fixed SOCKS5 server on port 1082. This configuration enables the threat actor to monitor all user activity, as all browser requests are channeled through this proxy, except for those to localhost addresses. Despite being removed from the Chrome Web Store, 221 extensions remain active, posing ongoing risks.
Further complicating matters, these extensions reportedly originate from a Russian subscription-based VPN service, identifiable through shared taxpayer numbers and Windows build paths. The extensions mimic legitimate services but incorporate telltale signs of fraudulent activity, such as nonexistent premium features and misleading DNS evasion tactics.
Ongoing Challenges in Browser Security
The issue highlights broader challenges in ensuring browser security. The extensions not only deceive users by presenting fake interfaces and animations but also attempt to bypass Chrome Web Store verification by providing misleading information. This includes false claims about data transmission and user tracking.
In addition, Netskope Threat Labs has reported the re-emergence of a previously removed Chrome extension, “AI Sidebar with Deepseek, ChatGPT, Claude, and more.” This extension, initially removed for prompt poaching, returned with a monetization update that redirects users via affiliate links every time the extension updates or uninstalls.
The continued efforts to exploit browser extensions underline the importance of vigilance in cybersecurity. Users are advised to be cautious with extensions and regularly review their permissions and origins to mitigate potential threats.
