Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
737 VPN Extensions Expose Users to Proxy Risks

737 VPN Extensions Expose Users to Proxy Risks

Posted on August 12, 2026 By CWS

A significant security concern has emerged with the identification of 737 free VPN and proxy extensions that are primarily targeting users who speak Russian. These extensions are designed to intercept internet traffic by redirecting it through a proxy network, potentially compromising user privacy. The findings were revealed by cybersecurity researcher Kush Pandya.

Widespread Installation and Brand Impersonation

The malicious extensions have been distributed across approximately 40 developer accounts on the Chrome Web Store, accumulating over 75,000 installations. Notably, 274 of these extensions mimic 66 well-known VPN and privacy service brands, such as Proton VPN, NordVPN, and Surfshark, as reported by security firm Socket.

The extensions route the entire browsing session through SOCKS5 proxies, with 520 out of 522 extensions using the same proxy infrastructure. This setup allows the threat actor to act as an intermediary, observing all browser traffic, source IPs, and TLS SNI values, which raises significant privacy concerns.

Technical Exploits and Privacy Concerns

The operational mechanism involves setting the Chrome browser’s proxy settings to a fixed SOCKS5 server on port 1082. This configuration enables the threat actor to monitor all user activity, as all browser requests are channeled through this proxy, except for those to localhost addresses. Despite being removed from the Chrome Web Store, 221 extensions remain active, posing ongoing risks.

Further complicating matters, these extensions reportedly originate from a Russian subscription-based VPN service, identifiable through shared taxpayer numbers and Windows build paths. The extensions mimic legitimate services but incorporate telltale signs of fraudulent activity, such as nonexistent premium features and misleading DNS evasion tactics.

Ongoing Challenges in Browser Security

The issue highlights broader challenges in ensuring browser security. The extensions not only deceive users by presenting fake interfaces and animations but also attempt to bypass Chrome Web Store verification by providing misleading information. This includes false claims about data transmission and user tracking.

In addition, Netskope Threat Labs has reported the re-emergence of a previously removed Chrome extension, “AI Sidebar with Deepseek, ChatGPT, Claude, and more.” This extension, initially removed for prompt poaching, returned with a monetization update that redirects users via affiliate links every time the extension updates or uninstalls.

The continued efforts to exploit browser extensions underline the importance of vigilance in cybersecurity. Users are advised to be cautious with extensions and regularly review their permissions and origins to mitigate potential threats.

The Hacker News Tags:browser security, Chrome extensions, Chrome Web Store, Cybersecurity, data privacy, internet security, Privacy, proxy servers, security risks, VPN

Post navigation

Previous Post: Fake CCleaner Download Spreads GhostDesk Spyware
Next Post: SharePoint Exploit Emerges Following PoC Release

Related Posts

Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension The Hacker News
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS The Hacker News
GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards The Hacker News
China-Linked Group Uses BPFDoor to Spy on Telecoms China-Linked Group Uses BPFDoor to Spy on Telecoms The Hacker News
Weekly Security Highlights: AI Breaches, Bitcoin Heist, and More Weekly Security Highlights: AI Breaches, Bitcoin Heist, and More The Hacker News
Why 2026 Will be the Year of Machine-Speed Security Why 2026 Will be the Year of Machine-Speed Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark