Malicious VPN Extensions Turn Browser Users Into Residential Proxy Servers
Thirty-one malicious Chrome VPN extensions enrolled about 356,000 browsers into a remotely controlled residential proxy network.
RiskyPlugins reported an ongoing cluster of 31 Russian-language Chrome extensions, marketed as VPNs for blocked sites, that route browser traffic through remotely controlled proxies. About 356,000 users are affected, including roughly 200,000 installs of a RuTracker VPN extension published across three Google accounts. The extensions request proxy, all-URL, and webRequestAuthProvider permissions and load obfuscated Proxy Auto-Configuration data from GitHub Pages, Blogspot, Telegram, and Google Docs, allowing operators to change destinations without an update. Total VPN reportedly proxies all traffic, and a paid VIP tier costs 299 Russian roubles via api.hhos.ru and mainapi.store.
- RiskyPlugins found 31 Russian-language Chrome VPN extensions sharing one codebase.
- About 356,000 users are affected; the largest extension has roughly 200,000 installs.
- Remote PAC configs from GitHub Pages, Blogspot, Telegram, and Google Docs change routes.
- Total VPN proxies all browser traffic, exposing metadata to operator-chosen servers.
- Teams should block known extension IDs and review Chrome proxy settings.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | de34.rapidstaticserve.cc | um servers: de8.staticvaultcdn.org de4.servefaststatic.work de34.rapidstaticserve.cc However, this overlap is not definitive proof of attributio |
| domain | de4.servefaststatic.work | sed for Browsec VPN premium servers: de8.staticvaultcdn.org de4.servefaststatic.work de34.rapidstaticserve.cc However, this overlap is not defin |
| domain | de8.staticvaultcdn.org | es with the hostnames used for Browsec VPN premium servers: de8.staticvaultcdn.org de4.servefaststatic.work de34.rapidstaticserve.cc However, |
| domain | dtextension.blogspot.com | om various public sources, including: s-extension.github.io dtextension.blogspot.com t.me/liservers Google Docs-hosted content The configuration |
| domain | mainapi.store | activities have been linked to the domains api.hhos.ru and mainapi.store. Researchers observed three HTTPS fallback hostnames in the |
Full article557 words · extracted from gbhackers.com · click to collapse
A cluster of 31 Russian-language Chrome extensions, marketed as “VPN for X” tools, has been discovered using a shared codebase to redirect browser traffic through remotely controlled proxy infrastructure.
This ongoing campaign, revealed on September 19, 2026, has affected about 356,000 users, effectively turning their installed browsers into nodes in a residential proxy network.
Researchers at RiskyPlugins identified the extensions across three linked Google publisher accounts: [email protected], [email protected], and [email protected].
These applications claim to restore access to various blocked services, including RuTracker, YouTube, Telegram, Instagram, ChatGPT, Claude, Netflix, Discord, Spotify, LinkedIn, and X.
The largest extension in this group, titled “РуТрекер VPN, расширение для доступа к сайту,” accounts for roughly 200,000 installations. Other noteworthy extensions include VPN for ChatGPT, Total VPN, VPN for Gemini, VPN for Telegram, and VPN for Claude.
Malicious VPN Extensions
The extensions request highly sensitive browser permissions, such as proxy control, access to all URLs, and the use of webRequestAuthProvider.
Their code configures browser traffic through a Proxy Auto-Configuration (PAC) script instead of relying on a fixed, embedded server list.
This design gives operators a significant advantage: they can change proxy destinations and decide which traffic routes through their infrastructure after installation, without publishing an extension update or seeking renewed user consent.
RiskyPlugins reported that the remote proxy configuration is retrieved from various public sources, including:
- s-extension.github.io
- dtextension.blogspot.com
- t.me/liservers
- Google Docs-hosted content
The configuration is obfuscated using a Caesar-shift transformation layered over Base64 encoding. Once decoded, it reveals proxy endpoints and shared credentials with monthly expiration periods.
While many extensions claim to proxy traffic only for specific blocked platforms, the “Total VPN” extension reportedly routes all browser traffic. This behavior exposes users’ browsing metadata and potentially session-related traffic to infrastructure selected by an external operator.
The campaign also includes a paid “VIP” service priced at 299 Russian roubles. Subscription-related activities have been linked to the domains api.hhos.ru and mainapi.store.
Researchers observed three HTTPS fallback hostnames in the decoded configuration that share similarities with the hostnames used for Browsec VPN premium servers:
- de8.staticvaultcdn.org
- de4.servefaststatic.work
- de34.rapidstaticserve.cc
However, this overlap is not definitive proof of attribution. Researchers noted that they could not confirm who operates the cluster of extensions or verify whether the campaign can successfully access those servers.
Detection and Response
Security teams should search for the affected Chrome extension IDs and inspect managed endpoints for outbound connections to the configuration and subscription hosts.
A connection to a public GitHub Pages site, Blogspot page, Telegram channel, or similar source shortly after installing a VPN extension may indicate this proxy-farming activity.
Organizations should block the known extension IDs through Chrome Enterprise policies, remove identified extensions, and review proxy settings and browser extension inventories.
Users should avoid “VPN for one website” extensions that request permission to proxy all sites, particularly when routing decisions are downloaded from operator-controlled remote sources after installation.
These findings are based on RiskyPlugins’ analysis of the campaign’s extensions, configuration sources, and archived CRX samples. The supplied source URLs could not be retrieved for independent verification at the time of publication.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.