With most VPNs requiring a subscription or capping the free usage to a couple of gigabytes per day, it’s easy to see why many people try to get their hands on a free VPN extension. But as the saying goes, if something is free, your data is the price you pay. And it turns out that the researchers at Socket just uncovered 737 fake VPN and proxy extensions on the Chrome Web Store.

Between them, they racked up more than 75,000 installs before anyone noticed, and most of the people installing them were Russian speakers just trying to reach Instagram, YouTube, or ChatGPT.

Once unsuspecting users enable the VPN, it points every tab you open to a single relay the operator controls. And since these are fake extensions, there’s no per-site exception, no split tunneling, nothing. The researchers say that the server is sitting in a spot where it can “read every destination, every TLS SNI value, the victim’s source IP, and any request body sent over plain HTTP.”

What this means is that if you visit unsecured HTTP sites, then fake VPN operators can see the pages you visit and where you are connecting from. All the data passes through a machine that you have no control over and did not agree to trust in the first place.

Adding to that, some of these VPNs disguise themselves as trusted brands like Proton VPN, NordVPN, Surfshark, and Cloudflare’s 1.1.1.1. So for users who aren’t careful, it’s easy to miss the warning signs that would otherwise let them know they’re not using the real thing.

fake-1-1-1-1-vpn-extension

Moreover, this isn’t the first time that we’ve seen bad actors hide behind a friendly-looking add-on either. We covered a batch of wallpaper extensions faking Google search traffic while quietly logging users, and separately, a pair of “free VPN” extensions that were caught siphoning off clipboard contents.

Apart from just logging traffic, these VPNs also tried tricking users into paying for premium servers in multiple countries, even though none of them actually existed. Paying users were essentially giving the operators money to access their traffic.

Google has pulled more than 200 of the extensions, but over 500 are reportedly still sitting in the store. And since extensions can rewrite themselves through a background update, even a clean-looking one can turn later, something we saw play out with a 900,000-user extension that was one update away from watching people.

If there’s one takeaway from this, it’s that you should always double-check the extensions you choose to install on your browser, especially the developer details and reviews, before installing anything.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
2912 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.