Threat Intelligence

737 Fake VPN Extensions Found Hijacking Browser Traffic in Chrome Web Store

The Hacker News · 13 Aug 2026
Key Takeaway Australian small businesses should review installed browser extensions regularly and avoid free VPN or proxy tools from unverified developers, especially on devices used for work.

Researchers have uncovered a large-scale campaign involving 737 free VPN and proxy browser extensions on the Chrome Web Store, collectively installed more than 75,000 times. The extensions, published across at least 40 different developer accounts, were designed to appeal mainly to Russian-speaking users trying to access blocked websites and services.

Rather than simply providing a VPN service, these extensions intercept a user's browser traffic and route it through proxy servers controlled by the attackers. Of the extensions analysed, 274 were found impersonating 66 legitimate brands, making them harder for everyday users to identify as fraudulent.

While this campaign primarily targeted Russian-speaking users, the incident is a reminder that browser extensions—especially free VPN and proxy tools—can carry serious hidden risks. Once installed, malicious extensions can see and manipulate all traffic passing through the browser, including logins, passwords, and sensitive business data, without the user ever realising it.

Chrome Extensions VPN Security Browser Security Malware Data Privacy

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.