Zero Day Room
Live
Incidents

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies

A set of 737 free VPN and proxy extensions have been found to target Russian-speaking users, intercepting browser traffic and routing it through a proxy infrastructure.

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies

## 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies A recent discovery has revealed that a massive set of 737 free VPN and proxy extensions have been found to target Russian-speaking users seeking access to blocked services. These extensions, published across at least 40 Chrome Web Store developer accounts, have racked up 75,486 installs. The extensions in question have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, and Google's Outline. Security researcher Kush Pandya stated that the extensions route the user's entire browser session through SOCKS5 proxies operated by a single provider. The vast majority of the extensions have been found to route users' entire browser sessions by setting "chrome.proxy.settings" to a fixed SOCKS5 server on port 1082. This places the threat actor in an adversary-in-the-middle (AitM) position to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP. Every extension that configures a proxy also comes with a bypass list that only includes loopback addresses, meaning every other browser request is funnelled through the SOCKS5 relay on port 1082 once the user connects to the purported VPN service. As many as 221 browser add-ons have been removed from the Chrome Web Store, while the remaining 516 extensions have been listed as active. The threat actor is said to be running a subscription VPN business in Russia, based on a 12-digit taxpayer number and the fact that some of them leak their Windows build path. The defining aspect of this activity is its attempt to impersonate established brands as opposed to offering it under their own name. Some of the other red flags include advertising paid tiers that do not exist, DNS-over-HTTPS blocklist evasion, and failing every connection attempt while showing a complete fake interface. The presence of comments that indicate a deliberate attempt to evade Chrome Web Store policies and the addition of a new remote-configuration layer after extension approval are also concerning. Furthermore, the threat actor has been attempting to game the Chrome Web Store review process by submitting identical justifications, stating "No data transmitted to external servers" or "No user tracking or logging". The development comes as Netskope Threat Labs highlighted the return of a Google Chrome extension named "AI Sidebar with Deepseek, ChatGPT, Claude, and more." months after it was removed for engaging in Prompt Poaching tactics. The clean-then-poisoned update sequence took place via Google's CRX content delivery network on July 31, 2026, pushing out a monetization scheme - a "surgical" 21-line addition - built around extension update and uninstall events. The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks, it pulled the rug again with a new update, this time containing a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. The return of this extension highlights the ongoing threat of malicious Chrome extensions and the need for users to remain vigilant when installing and using browser add-ons.

Related coverage

More from Incidents