Chrome Users Warned Over 737 Fake VPN and Proxy Extensions
More than 700 fake VPN and proxy extensions have been uncovered on the Chrome Web Store, with many impersonating well-known privacy services.
Security researchers at Socket identified more than 737 extensions posing as services including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1.
The extensions accumulated nearly 75,000 downloads and were connected to 40 publisher accounts and a shared analytics account.
Fake VPN extensions targeted Russian users
Most downloads reportedly came from users in Russia looking for ways to access blocked online services.
Socket believes the campaign aimed to direct users toward a subscription-based VPN service operating in Russia.
Researchers found that 520 extensions configured Chrome to route all browser traffic through SOCKS5 proxy servers on port 1082. Those proxies were controlled by the same provider.
This setup could allow the proxy operator to see users’ source IP addresses, destination services, TLS SNI information, and data from unencrypted HTTP requests.
Another 104 extensions resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS, which researchers said made the underlying infrastructure harder to investigate.
Extensions advertised fake premium VPN servers
Some extensions claimed to provide premium VPN servers in countries including Japan, Singapore, Canada, Australia, and Turkey.
Researchers found that the advertised connections did not necessarily exist. The extensions instead appeared designed to encourage users to purchase paid subscriptions.
Socket also found signs that operators deliberately tried to avoid detection. Some extensions reportedly provided misleading information to Chrome Web Store reviewers and added remote configuration capabilities after gaining approval.
Operators also used techniques that concealed proxy destinations from security researchers.
Socket could not fully analyze 212 extensions because they had already disappeared from the Chrome Web Store before researchers collected their code.
More than 500 extensions remained available
Google has removed more than 200 extensions linked to the campaign, but Socket reported that more than 500 remained available on the Chrome Web Store when it published its findings.
Researchers released a list of affected extension IDs so users can check installed Chrome extensions. Socket also recommends removing affected extensions and confirming that Chrome’s proxy configuration has returned to its normal settings.
In other security news, a critical SharePoint flaw is being exploited, while Microsoft has patched a WinSock vulnerability.
The ShieldBreak zero-day exploit can also affect fully patched Windows systems.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages