737 Fake VPN Chrome Extensions Exposed — Check If You're Affected

fake VPN Chrome extension

Security researchers at Socket found 737 Chrome extensions posing as free VPN and proxy tools that were secretly funneling users' entire browsing sessions through proxy servers controlled by a single, unidentified operator. If you've ever installed a free VPN extension from the Chrome Web Store without recognizing the brand, this is worth five minutes of your time today — not because you're necessarily affected, but because checking takes less time than reading the rest of this article.

Key Takeaway: 274 of these 737 extensions copied the names and branding of 66 real VPN and privacy services — including Proton VPN, NordVPN, Surfshark, and ExpressVPN — to look trustworthy. Once installed, 520 of the 522 extensions researchers examined routed every browser request through the same SOCKS5 proxy on port 1082, exposing the sites you visit, your IP address, and any unencrypted page data to whoever runs that proxy.

What Actually Happened

Researchers at Socket.dev spent time analyzing extension packages published under at least 40 different Chrome Web Store developer accounts. Together, those accounts had published 737 extensions marketed as VPN or proxy tools, pulling in a combined 75,486 installs. Of the extensions Socket could retrieve and inspect the code for — 522 out of the 737 — 520 configured Chrome to send all outbound traffic through a fixed SOCKS5 proxy server on port 1082, with the bypass list covering only local addresses. In plain terms: once you clicked "Connect," everything else you did in that browser went through someone else's server first.

Google has already pulled a portion of the listings — researchers reported roughly 200 removed — but several hundred were still live on the Chrome Web Store as of the most recent count. This is exactly the kind of research-backed browser threat we track in our guide to spotting data-stealing AI Chrome extensions, and the checking process below borrows the same core method.

Which Brands Were Impersonated

What the researchers found The number
Total fake VPN/proxy extensions identified 737
Developer accounts publishing them 40+
Combined installs across all extensions ~75,486
Extensions impersonating a known VPN brand 274
Real VPN/privacy brands impersonated 66 (including Proton VPN, NordVPN, Surfshark, ExpressVPN)
Extensions confirmed routing traffic through the same proxy 520 of 522 analyzed

What This Actually Exposes

Researchers were clear about the limits of what they could confirm, and it's worth being just as precise here rather than overstating the danger. Because most of the web runs on HTTPS, a proxy sitting in the middle generally can't read the actual content of your encrypted traffic — your passwords and page content stay protected in most cases. What the proxy operator can see is which sites you're visiting, your real IP address, and connection metadata (the TLS "SNI" value, which reveals the domain name even on an encrypted connection). Any plain HTTP traffic — increasingly rare, but not extinct — would be fully readable. Some extensions in the campaign also advertised premium server locations that researchers found didn't actually exist, and made unauthorized configuration changes after they'd already passed Chrome Web Store review.

Warning: The mere fact that an extension uses a proxy doesn't automatically make it malicious — that's literally how browser VPN extensions work. What makes this campaign different is the brand impersonation, the fake server locations, and dozens of unrelated "developers" all routing traffic through the exact same infrastructure. If an extension you installed shares a name with a well-known VPN but isn't published by that company's verified account, treat it as a red flag regardless of this specific story.

How to Check If You Have One Installed

  • Open chrome://extensions in your address bar
  • Turn on Developer mode in the top-right corner — this reveals each extension's full ID string, not just its display name
  • For every VPN or proxy extension listed, click Details and check the publisher name against the actual company's official website — not just the icon or display name, since both are trivial to fake
  • If the publisher can't be verified, or the extension has been renamed, remove it entirely rather than just disabling it
  • After removing anything suspicious, go to chrome://settings → System and confirm no proxy settings were left behind
Proof Block: Before publishing, capture a screenshot of chrome://extensions with Developer mode switched on (blur or crop out any of your own unrelated extensions if you'd rather not show your full list), plus a screenshot of the Socket.dev research post showing the extension/install counts.

If You Actually Want a VPN, Here's the Safer Path

The easiest way to avoid this entire category of problem is to stop searching the Chrome Web Store directly and instead install a VPN from the provider's own official website, where the download link is unambiguous. We put three major providers through direct testing for speed, price, and privacy in our head-to-head VPN comparison, which is a safer starting point than scrolling Chrome Web Store search results for "free VPN."

Quick Win: Bookmark the official download page of whichever VPN you actually trust. Going back to that bookmark instead of re-searching "VPN extension" in the Chrome Web Store removes the exact opening these fake listings depend on.
Pro Tip: Extensions that only request the "proxy" permission look harmless in the Chrome permissions prompt, which is exactly why this campaign passed store review as easily as it did. A short permissions list is not the same thing as a safe extension — check the publisher identity every time, not just what boxes it asks to tick.

Sourcing note: Figures and technical details in this article come from Socket.dev's original threat research report, with corroborating detail from Cyber Security News, The Hacker News, and gHacks. Install counts and removal numbers reflect what was publicly reported at the time of writing and may change as Google continues removing listings.

Author Image

Hardeep Singh

Hardeep Singh is a tech and money-blogging enthusiast, sharing guides on earning apps, affiliate programs, online business tips, AI tools, SEO, and blogging tutorials. About Author.

Next Post Previous Post