Skip to content
TechToolsHQ
NewsReviewsGuidesTech 101Tech SeriesToolsNewsletter
TechToolsHQ

Independent, research-driven tech coverage — breaking news, in-depth reviews, buying guides, and technical tutorials to help you understand and choose with confidence.

Explore
NewsReviewsGuidesTech 101Tech SeriesFree Tools
Legal
About UsOur AuthorsContact UsPrivacy PolicyTerms of ServiceCopyright & DMCAAffiliate DisclosureEditorial PolicyAdvertise With Us

© 2026 TechToolsHQ. All rights reserved.

News/Security/737 fake Chrome VPN extensions routed browser traffic through proxies
Security

737 fake Chrome VPN extensions routed browser traffic through proxies

Researchers found hundreds of Chrome extensions impersonating Proton VPN, NordVPN and others while sending users' traffic through servers run by one operator.

By Himanshu Bhatt· 4 min read· August 22, 2026

A terminal screen reading “DATA TRANSFER COMPLETE — CONNECTION CLOSED” above a backlit keyboard.
Key Takeaways · TL;DR
  • Chrome extensions were linked to one campaign, with 75,486 installs between them.
  • of them impersonated 66 real VPN and privacy brands, including Proton VPN, NordVPN and ExpressVPN.
  • of 522 analysed extensions routed nearly all browser traffic through SOCKS5 proxies on port 1082.
  • Google removed 221; 516 were still listed as live when researchers collected the data on 11 August 2026.
  • A VPN extension can see everything a VPN app can — check the publisher, not the logo.
☰ On this page(show)(close)
  • 1.What the extensions actually did
  • 2.Who was targeted, and by whom
  • 3.What Google has removed
  • 4.How to check what you have installed
On this page
  • 1.What the extensions actually did
  • 2.Who was targeted, and by whom
  • 3.What Google has removed
  • 4.How to check what you have installed

Security researchers at Socket have linked 737 Chrome extensions to a single campaign that impersonated well-known VPN brands while quietly routing users' browser traffic through servers the operator controlled. In research published on 11 August 2026, the extensions had accumulated 75,486 installs between them — and the people who installed them were, in most cases, specifically looking for privacy tools.

INFO

The short version If you installed a VPN extension from the Chrome Web Store rather than from the VPN provider's own site, check who published it. 274 of these extensions impersonated 66 real brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, CyberGhost, Windscribe, TunnelBear and Cloudflare's 1.1.1.1. A convincing logo is not evidence of anything.

What the extensions actually did

Of 522 packages the researchers analysed in depth, 520 configured Chrome's proxy settings to send almost all browser traffic through SOCKS5 proxies on port 1082. The bypass list — the set of addresses allowed to skip the proxy — contained only loopback addresses, meaning effectively everything else went through the operator's infrastructure. That placed whoever ran those servers in a position to observe, in Socket's words, "every destination, every TLS SNI value, the victim's source IP, and any request body sent over plain HTTP."

It is worth being precise about what that does and does not mean. HTTPS traffic remains encrypted, so the operator could not read the contents of most modern web requests. What it could see is the shape of someone's browsing: which sites they visited, in what order, from which IP address — plus the full contents of anything still travelling over plain HTTP. For a tool marketed as a privacy product, that is close to an exact inversion of the promise. The research documents this capability and position; it does not claim the data was sold or misused.

Who was targeted, and by whom

The campaign was not scattershot. Socket found 94% of it aimed at Russian-speaking users looking for ways to reach services blocked in their country, including Instagram, YouTube and ChatGPT. The researchers tie the extension network to a Russian VPN subscription service operating under the brand Муха VPN (Myxa VPN), describing the extensions as a funnel into that paid business: "The extension estate is that business' customer acquisition funnel."* The people most exposed here were, in other words, those with the strongest reason to want a VPN in the first place.

What Google has removed

At the point the researchers collected their data, 221 of the extensions had been removed from the Chrome Web Store and 516 were still listed as active, carrying 58,318 installs between them. Those are a snapshot from 11 August 2026 and will have moved since — removals continue, and an extension disappearing from the store does not uninstall it from a browser that already has it. If one of these is installed, it keeps working until you remove it yourself.

How to check what you have installed

Open chrome://extensions and look at every extension with network permissions, not just the ones you think of as VPNs. For each, check the publisher name and website against the provider's real domain — the store listing's logo and screenshots are trivially copied, but a mismatched or absent publisher domain is a genuine signal. The safest habit is to install VPN software from the provider's own site rather than searching the extension store, and to prefer the provider's desktop or mobile app over a browser extension where both exist: a browser extension only protects the browser, and an extension you cannot vouch for protects nothing at all.

INFO

The wider point A VPN is the one category of software where the product is trust. Any VPN, real or fake, sees where you go by design — that is how it works. The entire question is whether the operator can be trusted with it, which is why the things worth checking are ownership, jurisdiction, no-logs policy and independent audits, not the interface. Our guide to choosing a safe VPN covers what to look for, and are free VPNs safe? explains why the free end of the market is where this goes wrong most often.

Frequently asked questions

Were these extensions stealing passwords?
The research does not claim that. It documents that the operator was positioned to see every destination visited, TLS SNI values, users' source IP addresses, and the contents of any traffic sent over plain HTTP. HTTPS content stayed encrypted.
How do I know if I installed one?
Open chrome://extensions and check the publisher and website of anything VPN- or proxy-related against the provider's real domain. If the extension has been removed from the store it may still be installed and running.
Does removing the extension fix it?
Removing it stops the traffic routing. If you signed in or reused a password anywhere through it, change that password.
Are browser VPN extensions safe in general?
A legitimate one from a provider you have reason to trust is fine, but it only protects browser traffic. Where a provider offers a full app, that is the stronger choice.
Which brands were impersonated?
Socket names Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, Google's Outline, AmneziaVPN and AntiZapret among 66 brands in total.

The uncomfortable part of this story is not that fake VPNs exist — it is how well they scaled inside an official store, and how ordinary they looked. Extension marketplaces make publisher identity easy to imitate and hard for a normal user to verify, and until that changes, the check has to happen at the point of install. If you take one thing from this: get VPN software from the provider's own website, and treat the extension store as a place to confirm what you already chose, not a place to choose from.

Keep going

Where to go next

Guide

Are free VPNs safe?

Why the free end of the market is where this goes wrong.

Read
Guide

How to choose a safe VPN

The checklist: ownership, jurisdiction, no-logs, audits.

Read

Produced with AI assistance. Every figure was read from Socket's published research and independently cross-checked against Bitdefender's reporting on 19 August 2026. Reviewed by a human editor before publish.

Share
Continue Reading

Related Stories & Next Reads

Close-up of the Windows key on a black laptop keyboard.
Security

Microsoft patched a Windows zero-day North Korean attackers were already using

Himanshu Bhatt · 4 min read · Aug 24, 2026
Chart showing 281 free Android VPNs audited: 61 plaintext, 29 leaks, 246 trackers, 76 ad-ID tracking
Security

Researchers audited 281 free Android VPNs: most track you, dozens leak your data

Himanshu Bhatt · 5 min read · Aug 24, 2026
A paper cut-out of a human head labelled “AI”, filled with watching eyes.
Security

One click could make Microsoft Copilot leak your Gmail, Drive and Calendar

Himanshu Bhatt · 4 min read · Aug 21, 2026

Don't miss the next deep-dive

Weekly breakdowns of the tools students and builders actually use.

No spam·Unsubscribe any time·Privacy-first