Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    August 12, 2026

    A $36 billion lawsuit just turned Kalshi’s $40 billion valuation race into a federal market emergency

    August 12, 2026

    NASA Astronaut Mike Fincke Leaves NASA, Career Includes 4 Spaceflights

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
    • A $36 billion lawsuit just turned Kalshi’s $40 billion valuation race into a federal market emergency
    • NASA Astronaut Mike Fincke Leaves NASA, Career Includes 4 Spaceflights
    • Deploys Olympus and Artemis vessels to support strategic offshore operations in the Gulf of Mexico
    • How to make sure that no child is left behind | Primary schools
    • US inflation eases as food and fuel costs cool
    • Major Russian grain export terminal hit in Ukraine Black Sea port attack
    • Swinney calls for Burnham rethink on Chinese factory in Highlands
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 12, 2026Browser Security / Privacy

    A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure.

    The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare’s 1.1.1.1, and Google’s Outline, per Socket.

    The censorship circumvention extensions “route the user’s entire browser session through SOCKS5 proxies operated by a single provider,” security researcher Kush Pandya said. “520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure.”

    The vast majority of the extensions have been found to route users’ entire browser sessions by setting “chrome.proxy.settings” to a fixed SOCKS5 server on port 1082, placing the threat actor in an adversary-in-the-middle (AitM) position to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP.

    Cybersecurity

    Every extension that configures a proxy also comes with a bypass list that only includes loopback addresses (i.e., the localhost or 127.0.0.1″), meaning every other browser request is funnelled through the SOCKS5 relay on port 1082 once the user connects to the purported VPN service.

    As many as 221 browser add-ons have been removed from the Chrome Web Store, while the remaining 516 extensions have been listed as active. The threat actor is said to be running a subscription VPN business in Russia, based on a 12-digit taxpayer number and the fact that some of them leak their Windows build path (“C:UsersollobOneDriveДокументы1.myxa-work8.06.26-release.zip”).

    Ideally, the functionality is no different from a legitimate VPN or proxy service. The defining aspect of this activity is its attempt to impersonate established brands as opposed to offering it under their own name. Some of the other red flags include –

    • Advertising paid tiers (or premium locations) that do not exist
    • DNS-over-HTTPS blocklist evasion
    • Failing every connection attempt while showing a complete fake interface, including a working connecting animation and status indicator
    • Shipping an internal manual named “Промт для сотрудников” (translated to “Prompt for employees”) that instructs them to avoid putting the domain directly into “chrome.proxy.settings” (and instead provide only the resolved IP) and refrain from using a domain from another extension without separate instructions
    • Presence of comments that indicate a deliberate attempt to evade Chrome Web Store policies
    • Adding a new remote-configuration layer after extension approval
    • Attempts to game the Chrome Web Store review process by submitting identical justifications, stating “No data transmitted to external servers” or “No user tracking or logging”

    “For each affected user, while the extension is connected, every request passes through a server the threat actor controls,” Pandya said. “Whether the threat actor owns those proxy servers or resells capacity from an upstream provider is not resolvable from the extension code. If it resells, a further party is in the same position.”

    “What is established from the packages and from public infrastructure is the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and the post-approval code substitution.”

    Removed Chrome Extension Resurfaces with Monetization Scheme

    The development comes as Netskope Threat Labs highlighted the return of a Google Chrome extension named “AI Sidebar with Deepseek, ChatGPT, Claude, and more.” months after it was removed for engaging in Prompt Poaching tactics.

    Cybersecurity

    The clean-then-poisoned update sequence, spread across versions 1.7.2.0 and 1.7.3.0, took place via Google’s CRX content delivery network on July 31, 2026, pushing out a monetization scheme – a “surgical” 21-line addition – built around extension update and uninstall events.

    “The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks, it pulled the rug again with a new update,” the cybersecurity company said.

    “While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT.”

    caught check Chrome extensions Proxies Routing Traffic VPN
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Mindgard Raises $30 Million to Protect AI Systems

    SharePoint Vulnerability Exploited Shortly After PoC Release

    17 old software bugs that took way too long to squash

    The AI harness is the new attack surface

    Signal adds new security feature to thwart man-in-the-middle attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    August 12, 2026

    A $36 billion lawsuit just turned Kalshi’s $40 billion valuation race into a federal market emergency

    August 12, 2026

    NASA Astronaut Mike Fincke Leaves NASA, Career Includes 4 Spaceflights

    August 12, 2026

    Deploys Olympus and Artemis vessels to support strategic offshore operations in the Gulf of Mexico

    August 12, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    August 12, 2026

    A $36 billion lawsuit just turned Kalshi’s $40 billion valuation race into a federal market emergency

    August 12, 2026

    NASA Astronaut Mike Fincke Leaves NASA, Career Includes 4 Spaceflights

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.