Hundreds of Fake VPNs Flood Chrome Web Store
Socket's threat research team uncovers 737 suspicious Chrome extensions masquerading as popular VPNs and selling nonexistent servers.

Stock photo for illustration only, not from the actual event
- Socket researchers uncovered 737 suspicious VPN and SOCKS5 extensions on the Chrome Web Store.
- These extensions were published across 40 developer accounts and amassed 75,486 installs.
- 274 extensions plagiarized branding and logos from 66 reputable VPN platforms.
- Findings include fake premium tiers with nonexistent servers and zero internal license verification.
Think of VPNs like kitchen funnels that push your network traffic down a narrow tube of encryption, safely guiding your connection without leaking metadata everywhere. However, if the VPN itself acts as a honeypot to capture your data, you are trading multiple security risks for one guaranteed breach.
Recently, Socket's threat research team analyzed 737 suspicious Chrome extensions claiming to offer VPN and SOCKS5 proxy servers to protect online privacy. They uncovered paid applications selling access to nonexistent VPN servers, extensions hijacking proxies to track online activity, and multiple attempts to impersonate trusted providers like NordVPN and Surfshark.
Socket, a cybersecurity platform, found that these extensions were published by 40 developer accounts and had accumulated 75,486 installs from users on the Chrome Web Store before several were pulled down.

Stock photo for illustration only, not from the actual event
Out of the 737 extensions, Socket's team performed a detailed code analysis on 525 of them while the rest were already removed. The researchers immediately uncovered several critical issues:
- 274 out of 525 extensions plagiarized the branding and logo of 66 reputable VPN platforms, including Proton VPN, Surfshark, NordVPN, ExpressVPN, CyberGhost, and TunnelBear.
- Two extensions specifically impersonated AmneziaVPN and AntiZapret to bypass internet censorship.
- Each extension pointed to a fixed SOCKS5 proxy without split tunneling, routing all traffic through a single server.
- 104 extensions utilized DNS-over-HTTPS evasion techniques to bypass Chrome's blocklists.
Furthermore, many of these VPNs advertised paid tiers with private servers in countries like Japan, Singapore, Canada, Australia, and Turkey that simply did not exist. There was also no internal license verification to check if users actually paid for subscriptions.
"If Chrome Web Store rejects this because of automatically opening links, we can replace it with a notification offering to go to the Telegram bot."
Plaintext comment found in a fake extension
This incident demonstrates how malicious actors exploit low barrier-to-entry thresholds on official app marketplaces. By recycling developer accounts and leveraging trial-and-error tactics against review processes, bad actors can repeatedly deploy deceptive tools that threaten user security.
Users should always install browser extensions directly from official provider websites, thoroughly read user reviews, and inspect the developer accounts tied to the extensions before downloading any tools.
Source: Lifehacker
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment