Fake Chrome VPN Extensions: 737 Linked to One Operation
A Free VPN With a Hidden Network Behind It
A user installs a free VPN and clicks “Connect.” The familiar message of protection appears. Behind hundreds of different names, however, sat one shared infrastructure. Nearly all browser traffic passed through it.
Researchers at Socket linked 737 Chrome extensions to a single operation. It targets mainly Russian-speaking users.
Scale and Brand Impersonation
The extensions spread through at least 40 developer accounts. Together, they gathered 75,486 installs. Socket notes that the Chrome Web Store shows installs in rounded ranges. Thus, the figure is a sum of displayed values, not an exact count of users.
Among the finds, 274 extensions posed as 66 well-known VPN and privacy services. Targets included Proton VPN, NordVPN, Surfshark, AdGuard VPN, ExpressVPN, Windscribe, TunnelBear, Cloudflare 1.1.1.1, AmneziaVPN, and AntiZapret.
A Russian-Speaking Focus
The Russian focus runs through almost the entire network. Of 734 extensions in the original sample, 690 used Cyrillic in the name or description. Others mentioned services that are restricted in Russia.
Researchers studied the code of 522 packages in detail. Of those, 520 carried Russian-language descriptions.
How the Extensions Redirect Traffic
Most extensions redirect Chrome connections. Of the 522 packages examined, 520 set a fixed SOCKS5 proxy on port 1082. They do so through the standard chrome.proxy API.
The exclusion list held only local addresses such as localhost and 127.0.0.1. As a result, requests from every tab went through the proxy. The extensions offered no split routing for individual sites.
SOCKS5 Alone Is Not the Problem
Using SOCKS5 does not make an extension malicious. Browser VPNs and proxies legitimately rely on this mechanism.
The trouble lay in the combination of other signals. Those include mass copying of other brands, shared infrastructure, and hidden ways to locate servers. They also include paid locations that never worked, and identical technical templates across different publishers.
What the Proxy Operator Can See
A proxy server in this setup gains a powerful vantage point. The operator can see the user’s original IP address and the destination addresses. In addition, the operator can read TLS metadata available to the server. Any request sent over plain HTTP appears in full.
SOCKS5 adds no encryption of its own. Even so, the research showed no decryption of ordinary HTTPS traffic. Therefore, nothing supports claims that the operators read protected pages, passwords, or private messages.
Evasion and Remote Configuration
Some extensions tried to keep the proxy domain out of ordinary DNS queries. In 104 packages, the address first resolved through Google or Cloudflare DNS-over-HTTPS. Chrome then received a ready IP.
One published package even leaked an internal instruction in Russian. It told developers not to pass the domain directly into chrome.proxy.settings. Instead, they should use only the IP after name resolution.
Another 66 extensions could change their infrastructure without a new release. The code queried a preset address and followed an HTTP redirect. It then loaded its configuration from the new domain. Consequently, operators could move installed copies to another host without a store update.
Clues That Tie the Network Together
Traces inside the packages connected many seemingly independent add-ons. In 360 of the 522 studied extensions, the interface named Myxa VPN as the premium provider.
In 43 packages, an identical Windows build path survived, with a folder called myxa-work. Shared Yandex Metrica counters, mass domain registration, and identical code fragments completed the picture. Researchers found at least 102 related domains.
Broken Premium Promises
The paid features exposed further inconsistencies. The extensions offered premium servers in Japan, Singapore, Canada, Australia, and Turkey. Yet a check of all 200 matching names across 40 domains found no A record at all.
In some packages, license validation accepted any non-empty string. In ten extensions, the secret for building a token sat directly in the source code.
The Burenka VPN extension advertised servers in seven countries. However, 15 entries inside the package pointed to the non-routable address 0.0.0.0. Its connection handler always returned an error. The user saw a polished interface, but no working connection existed in the code.
Bypassing Chrome Web Store Review
Researchers found signs of attempts to pass Chrome Web Store review with simpler code. Extra mechanisms arrived later.
In one extension, developers accidentally left an archive of the previous version. That slip allowed a direct comparison of builds. The remote configuration mechanism appeared after initial approval, while the permission set stayed the same. In all, 49 extensions from 18 accounts, with 8,076 installs, received post-review updates.
Copied Justification Documents
Ten more packages held documents meant to justify permissions to store reviewers. Nine of these files were byte-for-byte identical, although they belonged to different publishers. The documents claimed that no data goes to outside servers and that no remote code runs.
Such behavior contradicts the Chrome Web Store policies. Those rules forbid impersonating another company and hiding or misrepresenting an extension’s real functionality.
Current Status and Limits of the Findings
By the time of data collection, Google had removed 221 of the 737 extensions. Another 516 remained published. Together, they showed 58,318 installs.
The researchers state the limits of their conclusions clearly. The analysis covered client-side code and open infrastructure. Hence, no evidence shows that operators stored, sold, or passed on user traffic.
The research does confirm several facts:
- A different routing scheme than users were told
- Copying of well-known brands
- Premium servers that do not exist
- Shared infrastructure across publishers
- Code changes after the initial review
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.