Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Hundreds of fake Chrome VPN extensions impersonating NordVPN, Proton, and more caught hijacking your traffic

Socket's Threat Research Team uncovered 737 fake Chrome VPN extensions impersonating major brands and rerouting browser traffic through their own proxies.

Hundreds of fake Chrome VPN extensions impersonating NordVPN, Proton, and more caught hijacking your traffic

A massive wave of counterfeit VPN extensions has been detected on the Chrome Web Store, with over 737 free extensions targeting popular services like NordVPN and Proton VPN, according to Socket's Threat Research Team. The extensions, originating from a single Russian VPN subscription business named Myxa VPN, have amassed more than 75,000 combined installs, primarily among Russian-speaking users.

The extensions act as a funnel, enticing users toward a paid subscription, but many of the paid promises are false. The core trick is that these extensions route all browser traffic through servers the operators control, without encryption, enabling them to observe user activity, including TLS SNI metadata, IP addresses, and unencrypted HTTP data.

While some extensions resolve their proxy addresses through Cloudflare or Google DNS-over-HTTPS, 104 of them directly hand Chrome a raw IP, making the operators' servers harder to detect. The threat remains active, with 221 extensions removed and 516 still listed on the Chrome Web Store. If you suspect you have installed one of these fake VPNs, Socket advises removing the extension, checking your browser's proxy settings, and changing any credentials entered while using the compromised extension.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech