700+ Fake VPN Extensions Found on the Chrome Web Store

Researchers found 737 fake VPN Chrome extensions routing browser traffic through one operator's proxies. Here is how to check yours and what to remove.
Brand:Google
Chrome logo over a grid of extension icons marked with red warning shields

If a free VPN extension is sitting in your Chrome toolbar, check who published it before you trust it with another browsing session. On August 11, 2026, researchers at Socket reported a campaign of 737 fake VPN and proxy extensions published to the Chrome Web Store from at least 40 developer accounts. At the time of the analysis, 516 of them were still live.

The extensions carried 75,486 installs in total, and 274 of them copied the names or branding of 66 real VPN and privacy products, including NordVPN, Proton VPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1.

The mechanics are the same across almost the entire set. Of the 522 packages retrieved for code analysis, 520 configure Chrome to push every browser request through a fixed SOCKS5 proxy on port 1082, run by the operator. There is no split tunneling and no added encryption. Once the user clicks Connect, the operator’s server sits between the browser and every site visited, in a position to see the destinations, the user’s real IP address, and anything typed into a page that is not HTTPS. The researchers are careful on one point: they analyzed only the extension code and do not claim the data was actually collected or misused. The position itself is the finding.

The fraud goes further than the proxy. Paid tiers advertised premium servers in Japan, Singapore, Canada, Australia, and Turkey. The researchers tested 200 of those hostnames and not one resolved. They were selling servers that do not exist. One extension, published as Burёnka VPN, ships a complete interface with a connecting animation over a connection routine hardcoded to fail every attempt.

The campaign also worked around the store’s defenses. 104 extensions resolve their proxy addresses through DNS over HTTPS and hand Chrome a raw IP, so blocklists never see the operator’s domains. 49 extensions received code changes after passing review, and several submitted identical statements to reviewers claiming no data leaves the browser.

The report traces the whole estate to a single operation, a Russian subscription VPN business trading as Myxa VPN. Around 94 percent of the extensions target Russian-speaking users trying to reach blocked services, which is why the campaign drew little attention elsewhere. Google had removed 221 extensions by the time the data was collected, including 14 of the 15 that Palo Alto Networks named in a June 5 report. The publisher accounts behind them kept publishing. A new Chrome Web Store developer account costs 5 dollars.


If one of these is in your browser

Remove any VPN extension you cannot tie to its real publisher, then open Chrome’s settings, search for “proxy”, and confirm nothing is still routing your traffic.

The cleanup takes a few minutes:

  1. Open chrome://extensions and remove any VPN or proxy extension whose publisher you cannot verify against the brand it claims to be.
  2. Search Chrome’s settings for “proxy” and confirm the configuration is back to normal after removal.
  3. Change any password you entered on a non-HTTPS page while the extension was connected, and treat browsing from that period as visible to a third party.

Before installing any VPN extension in the future, check that the listed developer is the company on the label. Ratings prove nothing here: one impersonator in this campaign was live with a 5.0 rating. Extensions that request proxy access deserve the same suspicion as anything asking to read your full traffic, a theme our Security & Privacy coverage keeps returning to.

The number to watch is not the removals. Google has taken down extensions but not the accounts publishing them, and the accounts behind them kept publishing after takedowns. Until the store starts removing publishers, expect the next batch.

Share:
Founder & Editor-in-Chief

Nasreddine is the founder of Softoto, a software download library and blog covering Windows, Mac, and mobile software. He spends his days verifying installers, tracking version histories, and separating real developer downloads from the fakes that outrank them. He tests what he can install himself, sources the rest from developer changelogs and advisories, and always says which one it was. Questions or corrections: contact@softoto.com

Discussion

(0)
{{ reviewsTotal }}{{ options.labels.singularReviewCountLabel }}
{{ reviewsTotal }}{{ options.labels.pluralReviewCountLabel }}
{{ options.labels.noReviewsLabel }}
{{ options.labels.newReviewButton }}
{{ userData.canReview.message }}