Home / Companies / Socket / Blog / Post Details
Content Deep Dive

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
5,838
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket researchers reported a large Chrome Web Store campaign involving 737 free VPN and proxy extensions across at least 40 developer accounts, with more than 75,000 estimated installs and 274 extensions impersonating 66 known privacy brands to attract largely Russian-speaking users seeking access to blocked services. Analysis of 522 retrieved packages found that 520 configured browser-wide SOCKS5 proxies controlled through shared infrastructure, potentially exposing users’ browsing destinations, source IP addresses, TLS metadata, and unencrypted HTTP traffic to the operators. The report links the extensions to the Myxa VPN subscription business through shared code, infrastructure, analytics identifiers, build paths, payment pages, and branding, while citing DNS-over-HTTPS resolution, remote configuration, post-approval code changes, reviewer statements, and coordinated publisher accounts as evidence of efforts to evade detection. It also found that advertised premium server locations did not resolve, some subscription mechanisms could not function as presented, and one extension was designed to fail all connections despite displaying a working interface. Although Google had removed 221 extensions, 516 remained live at the time of the research, highlighting concerns that low-cost developer accounts and fragmented enforcement enable similar extension networks to persist.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.