737 fake Chrome VPN extensions routed browser traffic through proxies
Researchers found hundreds of Chrome extensions impersonating Proton VPN, NordVPN and others while sending users' traffic through servers run by one operator.
By Himanshu Bhatt· 4 min read· August 22, 2026

- Chrome extensions were linked to one campaign, with 75,486 installs between them.
- of them impersonated 66 real VPN and privacy brands, including Proton VPN, NordVPN and ExpressVPN.
- of 522 analysed extensions routed nearly all browser traffic through SOCKS5 proxies on port 1082.
- Google removed 221; 516 were still listed as live when researchers collected the data on 11 August 2026.
- A VPN extension can see everything a VPN app can — check the publisher, not the logo.
On this page(show)(close)
Security researchers at Socket have linked 737 Chrome extensions to a single campaign that impersonated well-known VPN brands while quietly routing users' browser traffic through servers the operator controlled. In research published on 11 August 2026, the extensions had accumulated 75,486 installs between them — and the people who installed them were, in most cases, specifically looking for privacy tools.
What the extensions actually did
Of 522 packages the researchers analysed in depth, 520 configured Chrome's proxy settings to send almost all browser traffic through SOCKS5 proxies on port 1082. The bypass list — the set of addresses allowed to skip the proxy — contained only loopback addresses, meaning effectively everything else went through the operator's infrastructure. That placed whoever ran those servers in a position to observe, in Socket's words, "every destination, every TLS SNI value, the victim's source IP, and any request body sent over plain HTTP."
It is worth being precise about what that does and does not mean. HTTPS traffic remains encrypted, so the operator could not read the contents of most modern web requests. What it could see is the shape of someone's browsing: which sites they visited, in what order, from which IP address — plus the full contents of anything still travelling over plain HTTP. For a tool marketed as a privacy product, that is close to an exact inversion of the promise. The research documents this capability and position; it does not claim the data was sold or misused.
Who was targeted, and by whom
The campaign was not scattershot. Socket found 94% of it aimed at Russian-speaking users looking for ways to reach services blocked in their country, including Instagram, YouTube and ChatGPT. The researchers tie the extension network to a Russian VPN subscription service operating under the brand Муха VPN (Myxa VPN), describing the extensions as a funnel into that paid business: "The extension estate is that business' customer acquisition funnel."* The people most exposed here were, in other words, those with the strongest reason to want a VPN in the first place.
What Google has removed
At the point the researchers collected their data, 221 of the extensions had been removed from the Chrome Web Store and 516 were still listed as active, carrying 58,318 installs between them. Those are a snapshot from 11 August 2026 and will have moved since — removals continue, and an extension disappearing from the store does not uninstall it from a browser that already has it. If one of these is installed, it keeps working until you remove it yourself.
How to check what you have installed
Open chrome://extensions and look at every extension with network permissions, not just the ones you think of as VPNs. For each, check the publisher name and website against the provider's real domain — the store listing's logo and screenshots are trivially copied, but a mismatched or absent publisher domain is a genuine signal. The safest habit is to install VPN software from the provider's own site rather than searching the extension store, and to prefer the provider's desktop or mobile app over a browser extension where both exist: a browser extension only protects the browser, and an extension you cannot vouch for protects nothing at all.
Frequently asked questions
- Were these extensions stealing passwords?
- The research does not claim that. It documents that the operator was positioned to see every destination visited, TLS SNI values, users' source IP addresses, and the contents of any traffic sent over plain HTTP. HTTPS content stayed encrypted.
- How do I know if I installed one?
- Open chrome://extensions and check the publisher and website of anything VPN- or proxy-related against the provider's real domain. If the extension has been removed from the store it may still be installed and running.
- Does removing the extension fix it?
- Removing it stops the traffic routing. If you signed in or reused a password anywhere through it, change that password.
- Are browser VPN extensions safe in general?
- A legitimate one from a provider you have reason to trust is fine, but it only protects browser traffic. Where a provider offers a full app, that is the stronger choice.
- Which brands were impersonated?
- Socket names Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, Google's Outline, AmneziaVPN and AntiZapret among 66 brands in total.
The uncomfortable part of this story is not that fake VPNs exist — it is how well they scaled inside an official store, and how ordinary they looked. Extension marketplaces make publisher identity easy to imitate and hard for a normal user to verify, and until that changes, the check has to happen at the point of install. If you take one thing from this: get VPN software from the provider's own website, and treat the extension store as a place to confirm what you already chose, not a place to choose from.
Where to go next
Produced with AI assistance. Every figure was read from Socket's published research and independently cross-checked against Bitdefender's reporting on 19 August 2026. Reviewed by a human editor before publish.
Related Stories & Next Reads
Don't miss the next deep-dive
Weekly breakdowns of the tools students and builders actually use.
No spam·Unsubscribe any time·Privacy-first

