Mellowtel Browser Extensions Turn Homes Into Proxy Nodes
A Harmless Timer With a Hidden Job
The most innocent timer in Chrome could do very different work. Meanwhile, the user saw only a familiar start button.
The Spur team discovered that the Mellowtel SDK, embedded in browser extensions, turned home connections into nodes of a distributed network. That network loaded websites and passed their content to remote infrastructure.
How the Mellowtel SDK Works
Mellowtel embeds into extensions as a monetization tool. A background component opens a WebSocket connection to the service’s infrastructure. It then receives page-loading jobs and runs them through the user’s IP address.
The fetched content goes back to the operator. Therefore, the target site sees ordinary home-network traffic, not a data center request.
The Scale of the Network
The network proved far smaller than a million simultaneous nodes. Even so, its reach is large.
Earlier, SecureAnnex counted about 245 extensions for Chrome, Edge, and Firefox. Together, they held nearly one million installs. Spur first observed about 90,000 IP addresses tied to Mellowtel. After Google acted, the visible count fell to roughly 18,000.
Ordinary Tools as Cover
The sample included timers, alarms, and calculators. It also held QR tools and screenshot extensions. Other examples handled image and media downloads, price tracking, and social media work.
As of July 30, 2026, Spur still found add-ons that carried Mellowtel and the <all_urls> permission. That permission lets code run on any site and in every frame.
Weakening Browser Defenses
The SDK altered browser protections to load third-party pages inside hidden frames. Its code stripped the Content-Security-Policy and X-Frame-Options headers. It also removed several Cross-Origin headers and changed CORS behavior.
These headers normally stop other sites from embedding a page. Likewise, they limit data exchange between different origins.
Powers Beyond Page Loading
The extension permissions allowed more than page fetching. Spur found functions that inject externally supplied cookies, localStorage, and sessionStorage. It also found automated clicks and input, plus execution of operator-supplied JavaScript inside processed pages.
Jobs arrive after publication. As a result, real behavior can change without a new store version.
A Confused Deputy Flaw
Spur also described a confused deputy vulnerability. In it, an ordinary website can make a privileged extension component send an arbitrary HTTP POST request.
The response never returns to the attacking page, so this route cannot read data. Still, the request leaves from the user’s IP address and uses the extension’s network authority.
Why Residential Addresses Matter
Residential addresses carry value because sites treat them as normal visitors. Operators use such networks for scraping and account automation. They also use them for other tasks where data center addresses hit limits faster.
The connection owner, in turn, may face blocks, rate limits, or complaints. Those would stem from activity that a third-party SDK started.
Broad extension permissions have fueled other hidden schemes. In 2026, malicious extensions stole clipboard data. In addition, hundreds of fake VPNs rerouted traffic through SOCKS5 servers under their control. The Mellowtel case differs in one respect. Its service presents this infrastructure as a legitimate way to monetize free software.
The Vendor’s Position
Mellowtel states that its current SDK stays off by default. It starts only after explicit consent. The company also says it does not collect browsing history, user cookies, or personal data. According to Mellowtel, it loads public pages in an isolated session.
Spur, for its part, finds the disclosure of the SDK’s role unclear in many studied extensions.
Google’s Response and What Remains
Spur says Google took action against the affected extensions after contact. Versions without the SDK could stay in the store. After that intervention, the observed address count dropped from about 90,000 to a range of 15,000 to 18,000.
Spur does not publish a full list of current add-ons. Consequently, no single list lets anyone gauge the remaining network today.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.