Shubham Chaudhary737 Fake VPN Chrome Extensions Caught Hijacking Traffic via SOCKS5 Proxy TL;DR: A cybersecurity...
737 Fake VPN Chrome Extensions Caught Hijacking Traffic via SOCKS5 Proxy
TL;DR: A cybersecurity investigation found 737 malicious Chrome extensions posing as VPN tools. 520 of them silently rerouted all browser traffic through an attacker-controlled SOCKS5 proxy — no split tunneling, no exceptions.
For developers and security folks, this one's worth a closer look.
The technical breakdown:
The scale:
There's also a PowerShell one-liner in the full writeup for auditing installed extensions with proxy permissions across a fleet — useful if you're doing endpoint triage or building detection tooling.
Full technical writeup, IOCs, and enterprise hardening checklist:
https://www.xpert4cyber.com/2026/08/737-fake-chrome-vpn-extensions-spying.html
What's your team's approach to auditing browser extension permissions at scale? Curious how others are handling this.