737 Fake VPN Extensions Found Hijacking Browser Traffic in Chrome Web Store
Researchers have uncovered a large-scale campaign involving 737 free VPN and proxy browser extensions on the Chrome Web Store, collectively installed more than 75,000 times. The extensions, published across at least 40 different developer accounts, were designed to appeal mainly to Russian-speaking users trying to access blocked websites and services.
Rather than simply providing a VPN service, these extensions intercept a user's browser traffic and route it through proxy servers controlled by the attackers. Of the extensions analysed, 274 were found impersonating 66 legitimate brands, making them harder for everyday users to identify as fraudulent.
While this campaign primarily targeted Russian-speaking users, the incident is a reminder that browser extensions—especially free VPN and proxy tools—can carry serious hidden risks. Once installed, malicious extensions can see and manipulate all traffic passing through the browser, including logins, passwords, and sensitive business data, without the user ever realising it.