Fake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers
Thirty-one fake Chrome VPN extensions, with about 356,000 installs, route browser traffic through attacker-controlled proxies.
Risky Plugins disclosed 31 Russian-language Chrome extensions posing as VPNs for services such as RuTracker, YouTube, Telegram, and Netflix. The cluster, still active when documented on September 19, 2026, had about 356,000 installations, including roughly 200,000 for RuTracker VPN, and shared one codebase across three publishers. Each extension requests proxy and broad host permissions, then downloads a remotely changeable proxy list obfuscated with a Caesar shift over Base64. Operators can observe destinations and metadata; the Total VPN variant proxies all browser traffic. Researchers published hashes for 28 builds and treated hostname overlap with Browsec servers as an unproven lead.
- Risky Plugins found 31 extensions sharing one codebase across three publishers.
- RuTracker VPN alone accounted for about 200,000 installations.
- Proxy targets are downloaded remotely and hidden with Caesar-shifted Base64.
- The Total VPN variant routes all browser traffic, not one promoted site.
- SHA-256 hashes were published for 28 of the 31 extension builds.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | de34.rapidstaticserve.cc | names de8.staticvaultcdn.org, de4.servefaststatic.work, and de34.rapidstaticserve.cc—matched names associated with Browsec premium servers. Rese |
| domain | dtxtension.blogspot.com | investigate outbound connections to s-extension.github.io, dtxtension.blogspot.com, t.me/liservers, api.hhos.ru, and mainapi. The central warn |
Full article629 words · extracted from cybersecuritynews.com · click to collapse
A coordinated cluster of 31 Russian-language Chrome extensions that present themselves as convenient “VPN for X” tools while quietly steering browser traffic through remotely controlled proxy infrastructure.
Disclosed by Risky Plugins on September 19, 2026, the campaign remained active when documented and had accumulated roughly 356,000 installations, giving its operators a substantial traffic-routing footprint.
The extensions target users seeking access to blocked or restricted services, using names tied to RuTracker, YouTube, Telegram, Instagram, ChatGPT, Claude, Netflix, Gemini, Discord, Spotify, LinkedIn and other platforms.
Investigators linked the collection to three publisher accounts and found that all 31 extensions share one underlying codebase. The largest, RuTracker VPN, reportedly accounted for approximately 200,000 installations by itself.
Fake VPN Extensions Hijack Browser Traffic
Analysis conducted on September 3 and 4 found that each extension requests Chrome’s powerful proxy permission, registers a webRequest authentication handler, and claims host access across all URLs.
Chrome documents that its proxy API allows extensions to manage browser proxy settings, while the webRequest API can observe and intercept requests when the necessary permissions are granted.
Once installed, the extension creates a Proxy Auto-Configuration, or PAC, script that determines whether a requested URL should connect directly or pass through a designated proxy. Crucially, the proxy target list is not fixed inside the extension package.
Instead, it is downloaded from external infrastructure, allowing the operator to alter which websites are proxied and which servers receive the traffic without submitting an extension update.
Chrome’s own networking documentation confirms that PAC scripts execute logic to select proxy servers whenever a URL is fetched.
According to research published by Risky Plugins, researchers identified redundant configuration sources hosted on GitHub Pages, Blogspot, a Google document, and a Telegram channel.
The server list was concealed using a Caesar shift applied over Base64, a lightweight obfuscation technique that may frustrate simple inspection but provides no meaningful cryptographic protection.
Decoded data contained shared proxy credentials with monthly expiration dates. A paid VIP service priced at 299 roubles was also offered through api.hhos.ru and mainapi.
Most extensions appear designed to proxy traffic associated with a promoted service, but the “Total VPN” variant goes further by routing all browser traffic. That distinction materially increases exposure.
Proxy operators can observe connection metadata and destinations, while unencrypted HTTP content may be inspected or altered.
HTTPS still encrypts page content unless its trust protections are separately defeated, but sending sessions through unknown infrastructure creates opportunities for monitoring, blocking, redirection, and downstream abuse.
Risky Plugins archived and analyzed CRX packages for 28 of the 31 extensions and published per-build SHA-256 hashes to support detection.
The report also noted that three fallback hostnames de8.staticvaultcdn.org, de4.servefaststatic.work, and de34.rapidstaticserve.cc—matched names associated with Browsec premium servers.
Researchers explicitly treated this overlap as an investigative lead, not proof of ownership or attribution.
Users should remove any listed extension immediately, restart Chrome, and review browser and operating-system proxy settings for unfamiliar entries. They should also change credentials for sensitive accounts used during the exposure window, revoke active sessions where possible, and monitor for suspicious logins.
Enterprise defenders should block the published extension IDs, configuration domains, and subscription hosts, match archived hashes against managed endpoints, and investigate outbound connections to s-extension.github.io, dtxtension.blogspot.com, t.me/liservers, api.hhos.ru, and mainapi.
The central warning is straightforward: a single-site VPN demanding access to every URL and downloading routing instructions after installation should be treated as an unacceptable trust risk.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.