737 Chrome Extensions Routed Browsing Through One Proxy
Socket found 737 malicious Chrome VPN and proxy extensions, spread across at least 40 developer accounts and totaling 75,486 installs in the Chrome Web Store. 274 of them impersonated 66 known VPN and privacy brands, while 520 of 522 retrieved packages sent browser traffic through the same SOCKS5 proxy infrastructure.
The trick was simple: the add-on changed Chrome’s proxy settings so the whole browser session went through an attacker-controlled relay. Some versions also used DNS-over-HTTPS to look up the proxy host, which hides those lookups from basic network monitoring and leaves the operator in position to see everything the browser loads.
If users rely on browser VPN, proxy, or privacy extensions, the trust boundary is the extension itself: one approved add-on can become the network path for the whole session. In that model, store review does not guarantee the code stays what reviewers first saw, and a single operator can centralize interception across many branded listings.