Fake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A coordinated cluster of 31 Russian-language Chrome extensions that present themselves as convenient “VPN for X” tools while quietly steering browser traffic through remotely controlled proxy infrastructure.

Disclosed by Risky Plugins on September 19, 2026, the campaign remained active when documented and had accumulated roughly 356,000 installations, giving its operators a substantial traffic-routing footprint.

The extensions target users seeking access to blocked or restricted services, using names tied to RuTracker, YouTube, Telegram, Instagram, ChatGPT, Claude, Netflix, Gemini, Discord, Spotify, LinkedIn and other platforms.

Investigators linked the collection to three publisher accounts and found that all 31 extensions share one underlying codebase. The largest, RuTracker VPN, reportedly accounted for approximately 200,000 installations by itself.

Fake VPN Extensions Hijack Browser Traffic

Analysis conducted on September 3 and 4 found that each extension requests Chrome’s powerful proxy permission, registers a webRequest authentication handler, and claims host access across all URLs.

Chrome documents that its proxy API allows extensions to manage browser proxy settings, while the webRequest API can observe and intercept requests when the necessary permissions are granted.

Once installed, the extension creates a Proxy Auto-Configuration, or PAC, script that determines whether a requested URL should connect directly or pass through a designated proxy. Crucially, the proxy target list is not fixed inside the extension package.

Instead, it is downloaded from external infrastructure, allowing the operator to alter which websites are proxied and which servers receive the traffic without submitting an extension update.

Chrome’s own networking documentation confirms that PAC scripts execute logic to select proxy servers whenever a URL is fetched.

According to research published by Risky Plugins, researchers identified redundant configuration sources hosted on GitHub Pages, Blogspot, a Google document, and a Telegram channel.

The server list was concealed using a Caesar shift applied over Base64, a lightweight obfuscation technique that may frustrate simple inspection but provides no meaningful cryptographic protection.

Decoded data contained shared proxy credentials with monthly expiration dates. A paid VIP service priced at 299 roubles was also offered through api.hhos.ru and mainapi.

Most extensions appear designed to proxy traffic associated with a promoted service, but the “Total VPN” variant goes further by routing all browser traffic. That distinction materially increases exposure.

Proxy operators can observe connection metadata and destinations, while unencrypted HTTP content may be inspected or altered.

HTTPS still encrypts page content unless its trust protections are separately defeated, but sending sessions through unknown infrastructure creates opportunities for monitoring, blocking, redirection, and downstream abuse.

Risky Plugins archived and analyzed CRX packages for 28 of the 31 extensions and published per-build SHA-256 hashes to support detection.

The report also noted that three fallback hostnames de8.staticvaultcdn.org, de4.servefaststatic.work, and de34.rapidstaticserve.cc—matched names associated with Browsec premium servers.

Researchers explicitly treated this overlap as an investigative lead, not proof of ownership or attribution.

Users should remove any listed extension immediately, restart Chrome, and review browser and operating-system proxy settings for unfamiliar entries. They should also change credentials for sensitive accounts used during the exposure window, revoke active sessions where possible, and monitor for suspicious logins.

Enterprise defenders should block the published extension IDs, configuration domains, and subscription hosts, match archived hashes against managed endpoints, and investigate outbound connections to s-extension.github.io, dtxtension.blogspot.com, t.me/liservers, api.hhos.ru, and mainapi.

The central warning is straightforward: a single-site VPN demanding access to every URL and downloading routing instructions after installation should be treated as an unacceptable trust risk.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Fake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers appeared first on Cyber Security News.