
A new report has uncovered hundreds of malware-infected fake VPN extensions live on the Chrome browser. The tools claim to protect users’ digital identity but quietly send their traffic through servers controlled by operators. The research exposed 737 VPN and proxy extensions linked to at least 40 Chrome Web Store developer accounts.
Hundreds of malware-infected fake VPN extensions are live on Chrome Web Store
Socket’s Threat Research Team exposed the fake VPNs and claimed that about 270 of such VPN extensions were impersonating major brands like ProtonVPN and NordVPN. The extensions had been installed more than 75,000 times, primarily by Russian-speaking users. Moreover, Socket traced the group to a Russian VPN subscription business operating as Myxa VPN.
The security researchers connected the suspected extensions through a shared analytics account, clusters of domain registrations, common hosting, and leaked Windows build paths pointing to one project folder. Such tools were used to attract users and make them pay for premium plans.
Some claims, however, did not stand up. The group tested 200 premium hostnames across 40 domains. To make it more precise, the team included test servers advertised in Japan, Singapore, and Australia. Shockingly, none returned an A record, suggesting those servers did not exist in reality.
Users’ data was misrouted without their permission or acknowledgement
In its report, Socket claimed that the basic setup remained the same across all such “Fake” VPNs. When users pressed Connect, their browsing traffic was sent through a server controlled by the operator, with no per-site exceptions. The extensions did not add encryption. This basically means the tools offered none of the protection expected from a real VPN.
Such a setup gives operators complete access to the users’ browsing data. It could expose browsing history, TLS SNI metadata, source IP addresses, and data sent over unencrypted HTTP. Login details entered on a site without HTTPS protection could be exposed as well. Google reportedly removed 221 of the 737 extensions when Socket collected its data, but 516 were still listed.
To be safe from such hidden malware or tools, users are advised to install only legitimate tools. They must cross-check public reviews and licenses before using one.
The post Malware Fears Grow After Fake VPN Extensions Spread Across the Chrome Web Store appeared first on Android Headlines.