Security firm Socket published research on 11 August identifying 737 free VPN and proxy extensions on the Chrome Web Store that route your entire browser session through servers controlled by a single operator. Two weeks later, fake VPN extensions from that campaign are still installable: of four extension IDs from Socket’s published live list that we opened on 24 August, three still returned working Chrome Web Store listings — VPN Lagless, VPN free for chrome and a Russian-language listing called Тихий VPN. The fourth ID no longer carries a listing at all — its store page loads with no product name or description, so Google has removed that one since the report.

What Socket found in the fake VPN extensions
The 737 extensions were published from at least 40 Chrome Web Store developer accounts and had picked up 75,486 installs in total, using the store’s bucketed install counts rather than exact headcounts. When Socket collected its sample, 516 of them were still listed, carrying 58,318 of those installs.
Socket retrieved and read the code of 525. Of the 522 in its bulk sample, 520 pointed at the same SOCKS5 relay on port 1082, with a bypass list containing only loopback addresses — meaning every request from every tab goes through the operator’s machine once you press Connect, with no split tunnelling and no per-site exceptions. SOCKS5 configured this way adds no encryption of its own and does nothing about WebRTC or your operating system’s DNS.
274 of the extensions copied the branding of 66 real privacy products, among them Proton VPN, NordVPN, Surfshark, ExpressVPN, CyberGhost, TunnelBear, AdGuard VPN, Windscribe, Cloudflare’s 1.1.1.1 and Google’s own Outline. Socket also tested the 200 hostnames the paid tiers advertised in Japan, Singapore, Canada, Australia and Turkey across 40 domains. Not one returned a DNS A record — those were exactly the entries the extensions flagged as premium.
The economics are the reason this keeps happening. A Chrome Web Store developer account costs $5, so the accounts behind the campaign cost roughly the price of a takeaway meal and produced hundreds of listings. Socket’s finding is that Google removes extensions but not the publishers behind them.
Why a browser VPN extension can see everything
Chrome’s own documentation makes the limitation explicit. Adjusting an extension’s site-access permissions — the “On all sites” versus “On specific sites” control most people assume is the safety valve — does nothing here. Google’s Chrome Web Store help page states:
Extensions that change lower-level network access through VPNs or proxy settings aren’t affected by the change in permissions.
In other words, restricting a proxy extension to one website does not restrict what it proxies. This is the same structural problem behind the smart TV apps that were quietly routing strangers’ traffic through home connections: once something holds the network layer, its stated scope is a promise, not a control.
The campaign was aimed mainly at Russian-speaking users trying to reach blocked services, so most of the installs sit in that audience. The technique is not regional, though. Free proxy extensions find takers anywhere paid VPN subscriptions are an unwelcome monthly cost, and the store listing looks identical wherever you open it.
How to check whether you have one installed
- Type
chrome://extensionsin the address bar and press Enter. You can also reach it from the three-dot menu at the top right, under Extensions then Manage extensions. - Turn on the Developer mode toggle at the top right of that page. Chrome then prints a 32-character ID line under each extension’s name; without Developer mode on, the ID is hidden.
- Compare those IDs against the list of 516 IDs Socket published at the end of its report. Match the ID, not the name: Socket found the campaign regenerates variable names, function names and comments on every build, so logically identical extensions produce a different file hash each time and are published under assorted titles.
- Even if nothing matches, look hard at any free VPN or proxy extension you installed by searching the store rather than by following a link from the provider’s own website. Every one of the 66 impersonated brands has a real site with a real install link.
- Remove anything you cannot account for. The removal path is the same one we walked through when Microsoft’s new app started installing a Bing extension: Remove on the extension’s card, then confirm.
What to do if one was installed
Socket’s own remediation advice goes further than uninstalling. After removing the extension, open chrome://settings, search for “proxy”, and confirm your proxy configuration has gone back to normal. Change any credentials you typed on a non-HTTPS site while the extension was connected. And treat your browsing from that period as having been seen by a third party, because at the network level it was.
One honest caveat: Socket’s live-listing count is dated 11 August, and Google has been removing extensions from this campaign since. Our spot-check on 24 August confirms the estate is not gone, but the exact number live today is not something anyone outside Google can state precisely. If an ID from the list no longer resolves in the store, that does not mean the copy already sitting in your browser was uninstalled for you — removal from the store and removal from your machine are different things. Check the extensions page yourself. It takes about a minute.
Sources: Socket Threat Research, Google Chrome Web Store Help
