Fake Chrome VPN extensions proxy about 356,000 browsers
Thirty-one fake Chrome VPN extensions, tied to about 356,000 installs, route traffic through remotely controlled proxies.
Risky Plugins disclosed an ongoing cluster of 31 Russian-language Chrome extensions marketed as VPNs, documented as still active on September 19, 2026. They share one codebase across three publishers—called three Google accounts in the later report—and are associated with about 356,000 installations or users, including roughly 200,000 for RuTracker VPN, with promoted targets including RuTracker, YouTube, Telegram, and Netflix. The extensions request proxy and broad host permissions and fetch remotely changeable proxy configuration; one source describes Caesar-shifted Base64, while the other describes obfuscated PAC data hosted on GitHub Pages, Blogspot, Telegram, and Google Docs. Sources disagree on the effect: one says traffic is routed through attacker-controlled proxies that can expose destinations and metadata, while the other says the browsers were enrolled in a remotely controlled residential proxy network. Both agree the Total VPN variant proxies all browser traffic. Researchers published SHA-256 hashes for 28 of 31 builds, called Browsec hostname overlap unproven, and one report adds a VIP tier priced at 299 Russian roubles via api.hhos.ru and mainapi.store.
- Risky Plugins (also styled RiskyPlugins) documented 31 Russian-language Chrome extensions posing as VPNs, still active as of September 19, 2026.
- The cluster has about 356,000 installations in one report and about 356,000 affected users or browsers in the other, including roughly 200,000 for RuTracker VPN.
- The extensions share one codebase across three publishers, described in the second report as three Google accounts, and promote access to sites such as RuTracker, YouTube, Telegram, and Netflix.
- They request proxy and broad host permissions; one report specifically cites all-URL and webRequestAuthProvider permissions.
- Proxy targets are downloaded remotely: one report says a Caesar-shifted Base64 list, the other obfuscated PAC data from GitHub Pages, Blogspot, Telegram, and Google Docs.
- Both reports say the Total VPN variant proxies all browser traffic; they differ on whether this is hidden proxy routing or enrollment in a residential proxy network.
- SHA-256 hashes were published for 28 of 31 builds; hostname overlap with Browsec servers was treated as an unproven lead.
- A paid VIP tier is reported at 299 Russian roubles via api.hhos.ru and mainapi.store.
Coverage timelineoldest first · each row is one article
- · 1d agoFake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers
Cyber Security News· 71
Thirty-one fake Chrome VPN extensions, with about 356,000 installs, route browser traffic through attacker-controlled proxies.
- · 1d agoMalicious VPN Extensions Turn Browser Users Into Residential Proxy Servers
GBHackers· 62
Thirty-one malicious Chrome VPN extensions enrolled about 356,000 browsers into a remotely controlled residential proxy network.