hacker-news · Crawled Aug 12, 2026

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

Read original article ↗

AI Summary

A large-scale campaign involving 737 malicious Chrome VPN and proxy extensions has been uncovered, primarily targeting Russian-speaking users. These extensions impersonate 66 legitimate VPN brands and route users' entire browser traffic through SOCKS5 proxies controlled by a single threat actor, enabling adversary-in-the-middle (AitM) monitoring of destinations, IP addresses, SNI values, and unencrypted HTTP traffic. The extensions bypass Chrome Web Store policies by submitting false claims, using code obfuscation, and performing post-approval code substitution to hide malicious behavior, including non-existent premium tiers and affiliate monetization schemes.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.