737 Fake VPN Chrome Extensions Exposed — Check If You're Affected
Security researchers at Socket found 737 Chrome extensions posing as free VPN and proxy tools that were secretly funneling users' entire browsing sessions through proxy servers controlled by a single, unidentified operator. If you've ever installed a free VPN extension from the Chrome Web Store without recognizing the brand, this is worth five minutes of your time today — not because you're necessarily affected, but because checking takes less time than reading the rest of this article.
What Actually Happened
Researchers at Socket.dev spent time analyzing extension packages published under at least 40 different Chrome Web Store developer accounts. Together, those accounts had published 737 extensions marketed as VPN or proxy tools, pulling in a combined 75,486 installs. Of the extensions Socket could retrieve and inspect the code for — 522 out of the 737 — 520 configured Chrome to send all outbound traffic through a fixed SOCKS5 proxy server on port 1082, with the bypass list covering only local addresses. In plain terms: once you clicked "Connect," everything else you did in that browser went through someone else's server first.
Google has already pulled a portion of the listings — researchers reported roughly 200 removed — but several hundred were still live on the Chrome Web Store as of the most recent count. This is exactly the kind of research-backed browser threat we track in our guide to spotting data-stealing AI Chrome extensions, and the checking process below borrows the same core method.
Which Brands Were Impersonated
| What the researchers found | The number |
|---|---|
| Total fake VPN/proxy extensions identified | 737 |
| Developer accounts publishing them | 40+ |
| Combined installs across all extensions | ~75,486 |
| Extensions impersonating a known VPN brand | 274 |
| Real VPN/privacy brands impersonated | 66 (including Proton VPN, NordVPN, Surfshark, ExpressVPN) |
| Extensions confirmed routing traffic through the same proxy | 520 of 522 analyzed |
What This Actually Exposes
Researchers were clear about the limits of what they could confirm, and it's worth being just as precise here rather than overstating the danger. Because most of the web runs on HTTPS, a proxy sitting in the middle generally can't read the actual content of your encrypted traffic — your passwords and page content stay protected in most cases. What the proxy operator can see is which sites you're visiting, your real IP address, and connection metadata (the TLS "SNI" value, which reveals the domain name even on an encrypted connection). Any plain HTTP traffic — increasingly rare, but not extinct — would be fully readable. Some extensions in the campaign also advertised premium server locations that researchers found didn't actually exist, and made unauthorized configuration changes after they'd already passed Chrome Web Store review.
How to Check If You Have One Installed
- Open chrome://extensions in your address bar
- Turn on Developer mode in the top-right corner — this reveals each extension's full ID string, not just its display name
- For every VPN or proxy extension listed, click Details and check the publisher name against the actual company's official website — not just the icon or display name, since both are trivial to fake
- If the publisher can't be verified, or the extension has been renamed, remove it entirely rather than just disabling it
- After removing anything suspicious, go to chrome://settings → System and confirm no proxy settings were left behind
If You Actually Want a VPN, Here's the Safer Path
The easiest way to avoid this entire category of problem is to stop searching the Chrome Web Store directly and instead install a VPN from the provider's own official website, where the download link is unambiguous. We put three major providers through direct testing for speed, price, and privacy in our head-to-head VPN comparison, which is a safer starting point than scrolling Chrome Web Store search results for "free VPN."
Sourcing note: Figures and technical details in this article come from Socket.dev's original threat research report, with corroborating detail from Cyber Security News, The Hacker News, and gHacks. Install counts and removal numbers reflect what was publicly reported at the time of writing and may change as Google continues removing listings.
