Report Finds Over 700 Fake VPN Extensions on the Chrome Web Store With 75,000 Installs

Cybersecurity firm Socket has identified over 700 fake VPN extensions on the Chrome Web Store. Many of these steal user data or impersonate well-known providers.

Socket's threat research team analyzed 737 suspicious extensions that claimed to offer VPN and SOCKS5 proxy services. These were published under 40 developer accounts and had a combined 75,486 installs.

Some of the extensions are paid apps that sell access to VPN servers that do not exist. Others hijack the browser proxy to track user activity or impersonate providers such as NordVPN and Surfshark.

The extensions passed Chrome Web Store moderation by learning how to evade the review process.

Socket's Findings on Fake VPN Extensions and Chrome Web Store Evasion

Socket analyzed the code of 525 out of the 737 extensions, which together had 58,318 active Chrome installs at the time. The remaining 212 extensions had already been removed from the Web Store before the analysis. The researchers found several issues:

  • 274 of the 525 extensions plagiarized the branding and logo of one of 66 reputable VPN platforms, including Proton VPN, Surfshark, NordVPN, ExpressVPN, CyberGhost, and TunnelBear.
  • Two extensions specifically impersonated AmneziaVPN and AntiZapret, which are often used to bypass censorship and surveillance.
  • Each extension used a fixed SOCKS5 proxy without split tunneling or per-site controls. Once installed, all browser activity was routed through the same server.
  • 104 extensions used known DNS-over-HTTPS evasion techniques to bypass Chrome's blocklists by spoofing DNS records.
  • Many extensions advertised paid tiers with servers in Japan, Singapore, Canada, Australia, and Turkey. These servers did not exist, as their hostnames did not resolve in DNS lookups.
  • Premium subscriptions did not include any internal license verification to confirm payment, which is unusual for a paid service.
  • One extension, Bur?nka VPN, does not route any traffic through servers. It only displays a fake user interface.
  • Another extension included a plaintext code comment admitting it violated Web Store policy and outlining a plan to evade review instead of fixing the problem.

None of these extensions would be hard to flag in a thorough code review. The developers appear to have learned how to bypass Chrome's defenses by studying the review process and using trial and error.

Many of the developers had previous extensions removed by Chrome after a similar report from Palo Alto Networks in June. They quickly published new extensions using the same methods.

Since opening a new Chrome Web Store developer account costs $5, it cost about $200 to use 40 accounts to publish over 700 fake extensions that reached tens of thousands of users.

Most of the VPNs targeted Russian users trying to bypass regional censorship. As a result, incidents were not widely reported outside that group. When moderators did flag an extension, the developers responded with identical privacy justifications that offered little more than false reassurances to get the extensions restored.

This is not solely a regional threat, noting that the same playbook could be adapted to target users in the US, UK, EU, or elsewhere. Google itself issued a warning in 2025 about similar fake VPN activity on the Play Store for Android.

How Users Can Spot Fake VPN Chrome Extensions

Since app store reviews cannot be relied on alone, users can take steps to avoid fake extensions:

  1. Install extensions by following a link directly from the VPN provider's official website, not the Web Store search bar.
  2. Read user reviews before installing and avoid extensions with frequent complaints about security issues. Developer account tied to the app, confirming it is officially associated with the VPN provider and checking whether their other apps have se
  3. Use a tool such as WhatIsMyIPAddress.com to confirm that your visible IP address matches what the extension displays.x
  4. Run a DNS leak test while the VPN is active to confirm it encrypts DNS queries. If your real IP, location, or ISP appears, treat it as a red flag

Socket's report covers extensions that were active on the Chrome Web Store at the time of analysis, with 212 already removed before the review. This pattern suggests weak security reviews on the Web Store, and that developers have repeatedly returned with new accounts after removals.

Google has not said whether it will change its review process in response. Users should verify VPN extensions themselves instead of relying on store moderation.

Thank you for being a Ghacks reader. The post appeared first on gHacks.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论