Fake Chrome VPN Extensions Hijack Users' Traffic Across a Coordinated 31-App Spy Ring
Researchers found 31 Chrome extensions posing as VPNs that share one codebase and let their operators quietly change where users' browser traffic goes after install.

Hundreds of thousands of Chrome users installed what looked like simple VPNs for unblocking YouTube, Telegram or ChatGPT. What they actually got was a remote-controlled routing system whose operators can decide, at any moment, which of their traffic flows through someone else's servers.
Researchers at RiskyPlugins identified 31 Chrome extensions sold as site-specific VPNs that all run on the same codebase. Together they have about 356,000 installs. One of them, RuTracker VPN, accounts for roughly 200,000 on its own.
One codebase, many disguises
The extensions came from three publisher accounts and were mostly listed in Russian. Each promised to unlock one service: YouTube, Telegram, Instagram, ChatGPT, Claude, Netflix or RuTracker. A handful skipped the VPN branding entirely and posed as a job-search helper, a Telegram photo tool or a Wikipedia utility. Some offered a VIP tier for 299 rubles.
Under the hood they all asked for the same powerful permissions: proxy control, webRequestAuthProvider, and host access to every URL. That combination lets an extension reroute any site a user visits and answer proxy login prompts silently.
Routing that changes after install
The clever part is where the instructions live. A PAC script decides which traffic goes to a proxy, but the list of proxy servers isn't baked into the extension. It is downloaded after installation from GitHub Pages, Blogspot, a Google Doc and a Telegram channel, hidden behind base64 encoding and a Caesar shift.
That means the operators can point users at new servers, or widen the scope of what gets proxied, without ever pushing an update through the Chrome Web Store review process. One variant, Total VPN, already routes all browser traffic rather than a single site.
The researchers archived CRX file hashes for 28 of the 31 extensions. They also noticed that three fallback hostnames overlapped with premium server names used by Browsec, a commercial VPN, but they flag that only as a lead to investigate, not proof of who is behind the ring.
What the report doesn't show
RiskyPlugins did not establish that data was stolen, and nothing in the findings shows HTTPS content being decrypted. The risk is control: an unknown operator holds a switch over where your browsing goes, and can flip it whenever they like. Extensions quietly holding broad powers keep turning into attack surfaces, as with the Plugin4Shell flaw hitting AI agents.
Anyone who installed a single-purpose VPN extension from these listings should open chrome://extensions, check against the researchers' list, and remove any match.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free