737 Malicious Chrome VPN Extensions Exposed for Hijacking Browser Traffic
evilsocket · x · 2026-08-13
The threat research team at cybersecurity firm Socket uncovered a sprawling network of 737 malicious Chrome VPN extensions impersonating legitimate privacy brands.
These extensions hijacked users' browser traffic through a shared SOCKS5 infrastructure, accumulating over 75,000 installs. The campaign primarily targeted Russian-speaking users attempting to access blocked services like Instagram, YouTube, and ChatGPT. Investigations revealed that at least 274 extensions impersonated 66 well-known brands, including NordVPN and ProtonVPN. The operation was linked to a Russian VPN subscription business named Myxa VPN.
More from Safety
- Redwood and Anthropic release the Conceptual Reasoning Index (CRI) — RyanGreenblatt · 2026-08-13
- Dwarkesh Warns: Superintelligences Should Be Aligned to Individuals, Not Just Humanity — msg · 2026-08-13
- Grok 4.6 Launch Draws Criticism Over Missing Model Card and Safety Tests — Miles_Brundage · 2026-08-13
- Twitch Under Fire for Opting Creators Into AI Training by Default — zemotion · 2026-08-13
- Suno's BMG Partnership and Invisible Watermarks Slammed as Censorship — TomLikesRobots · 2026-08-13
- Cursor Accused of Turning into Spyware: Secretly Scanning Codebases with Grok — james_mtc · 2026-08-13