Interestana
Home/News/737 VPN Extensions Compromise Chrome User Traffic
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

737 VPN Extensions Compromise Chrome User Traffic

737 VPN Extensions Compromise Chrome User Traffic

A significant security vulnerability has been uncovered involving 737 free VPN and proxy extensions available on the Chrome Web Store, which were found to primarily target Russian-speaking users. These extensions were designed to intercept browser traffic and reroute it through a proxy infrastructure, compromising user privacy and security. The malicious extensions were published across at least 40 different developer accounts within the Chrome Web Store, collectively accumulating a substantial number of installations totaling 75,486. Further analysis revealed that 274 of these identified extensions were specifically designed to impersonate 66 legitimate services, likely to gain user trust and encourage installation. The primary objective of these extensions appears to be providing access to blocked services, a common use case for VPNs, while simultaneously exploiting users by routing their internet traffic through unauthorized proxy servers. This practice allows the operators of the proxy infrastructure to potentially monitor, collect, and misuse sensitive user data, including browsing history, login credentials, and financial information. The scale of the operation, involving hundreds of extensions and tens of thousands of installs, highlights a sophisticated and widespread effort to compromise user security. The discovery was made by security researchers who have been actively monitoring the Chrome Web Store for malicious applications. The researchers have not yet publicly disclosed the names of the specific extensions or the developer accounts involved, but they have indicated that they are working with Google to remove the malicious extensions from the store. Users who have installed any free VPN or proxy extensions on their Chrome browsers are strongly advised to review their installed extensions and uninstall any that appear suspicious or are not from a trusted provider. The incident underscores the persistent risks associated with using free, untrusted browser extensions, even those that appear to offer legitimate functionality. The motivation behind such attacks often includes data harvesting for sale on the dark web, facilitating further cybercrimes, or even conducting man-in-the-middle attacks. The Russian-speaking user base was likely targeted due to specific geopolitical or censorship-related internet access issues prevalent in certain regions, making them more susceptible to seeking out and installing such tools. The compromised traffic could be used for various illicit purposes, including identity theft, financial fraud, and the distribution of malware. The Chrome Web Store, while having security measures in place, remains a common distribution vector for malicious software due to its vast user base and the ease with which extensions can be uploaded. This incident serves as a stark reminder for users to exercise extreme caution when downloading any software, especially free extensions that promise enhanced online privacy or access to restricted content.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next