737 Fake "VPN" Extensions Were Spying On 75,000 People — Yours Might Be One

:detective: 737 Fake “VPN” Extensions Were Spying On 75,000 People — Yours Might Be One

They downloaded a “free VPN” to feel safe online. Instead they handed a stranger a live window into every single website they opened.

737 fake extensions · 75,000+ installs · 40 developer accounts · every click routed through one guy’s server on port 1082

Security team Socket found the whole thing. BleepingComputer and The Hacker News ran the story. It’s honestly bleak but also kinda fascinating.

hacker watching traffic

OKAY SO here’s the thing that made my stomach drop. A VPN is supposed to be the thing that HIDES you. You install it so nobody can see what you’re doing. And these 737 fakes did the exact opposite — they took every website you visited and quietly shipped it to a random server. Same trust, flipped inside out. That’s what makes this so nasty (and, if I’m honest, kind of a genius evil move).

🧩 Dumb Mode Dictionary
You’ll hear… It actually means…
VPN A tunnel that’s supposed to hide where you go online. These fakes faked the tunnel.
Browser extension A little add-on you click “Add to Chrome” for. Runs inside your browser with big powers.
Proxy / SOCKS5 proxy A middleman server your traffic passes through. Whoever runs it can watch it.
Traffic Literally the list of every site + page you open, plus your real location (IP).
TLS SNI Even on secure sites, this leaks the name of the site you’re visiting. They could see that.
Impersonation The fakes copied real brand names (Proton, Nord) so you’d trust them.
🎭 What these things were actually pretending to be

The fakes wore the costumes of the most trusted names in privacy:

  • Proton VPN, NordVPN, Surfshark, ExpressVPN
  • Even Cloudflare’s 1.1.1.1 — the free tool people install specifically to be safer

You search “Proton VPN Chrome,” you see a green icon and a familiar name, you click add. Done. Except it wasn’t Proton. It was a copy wearing Proton’s face. Real one lives here, for the record.

🔧 How the trick worked (simple version)
  • 520 of them flipped one hidden setting (chrome.proxy.settings) so nearly all your browsing got funneled through their server on port 1082.
  • The only thing they skipped was your own computer’s internal address. Everything else? Fair game.
  • That put the operator in “middle-man” position — they could see the sites you hit, your real IP, and any page that wasn’t fully encrypted, in full.
  • 104 of them used a sneaky trick (DNS-over-HTTPS via Google/Cloudflare) to hide their own server addresses so they’d be harder to block. Cheeky.
📊 The receipts
Number What it is
737 Fake VPN extensions found
75,000+ People who installed one
40+ Chrome Web Store developer accounts used
525 Extensions researchers pulled the code from
520 That rerouted basically all your traffic
1082 The port their spy-server listened on

Source breakdown and the brand list are in Socket’s writeup and BleepingComputer.

🌍 Who they went after

Mostly Russian-speaking users trying to reach blocked stuff — Instagram, YouTube, ChatGPT. People who needed a workaround the most, aka the people with the least room to be picky, got hit hardest. Researchers tied the network to a subscription outfit calling itself Myxa VPN. Classic move: the more locked-down your internet, the more desperate you are to click “install,” the easier you are to fool.

🗣️ What the timeline's saying
  • “The one app you install to NOT be watched was the watcher.” (couldn’t have said it better)
  • Security folks pointing out the boring truth: an extension can flip your proxy setting silently, and almost nobody checks chrome://extensions.
  • The uncomfortable takeaway going around: “free VPN” has always meant you’re the product. This is just the loudest proof yet. Good roundup of the year’s messes over at TechCrunch.

Cool. So Our “Privacy Tools” Are Now the Leak… Now What the Hell Do We Do? ಠ_ಠ

person checking browser settings

Here’s the fun part. A giant pile of people just learned their “safe” tool was fake, 75k of them need to clean up their browsers today, and Google’s about to nuke 737 listings — which means a wave of confused users about to go searching. Where there’s confusion and fear, there’s a person who fixes it for money. Let’s be that person (the legal, non-sketchy kind — we just talk sketchy).

🔎 The Extension Autopsy

Most people have 15 random add-ons they forgot installing. You become the person who opens the hood. Sit down (or screen-share), open chrome://extensions, cross-check every ID against Socket’s published list, yank the shady ones, and check nobody flipped their proxy setting. Charge per device. Small shops with 5–10 office laptops? Easy yes.

:brain: Example: A 24-year-old in Nairobi runs “browser health checks” over WhatsApp video for local shop owners, ~$4 a laptop, does 20 a week after posting one warning in a neighborhood Facebook group.

:chart_increasing: Timeline: First paid check in 3–4 days once you post the warning. Slows after ~8 weeks when the scare fades — so bundle it into a monthly “digital cleanup” so it repeats.

📋 Be the Verified-VPN Dictionary

Nobody knows which VPN extensions are the real ones anymore. So you build the cheat sheet: one clean page listing the genuine developer accounts (Proton’s real one, Nord’s real one, etc.) vs the known fakes, in ONE specific language nobody’s serving well yet. When people Google “is VPN safe,” your page is the answer. First good glossary owns the search spot.

:brain: Example: A student in Jakarta made an Indonesian-language “real vs fake VPN” table on a free Notion page, dropped legit affiliate links to the real tools, made steady beer money off installs — because he was first in his language.

:chart_increasing: Timeline: Ranks in ~2–3 weeks if the niche is thin. Copycats show up by month 3 — stay first by updating it every time a new fake list drops.

🪟 The Purge-Window Sprint

Google’s going to yank all 737. The second that happens, tens of thousands of people see “This extension has been disabled” and freak out. That panic is a countdown clock. Have a dead-simple “your fake VPN got removed — here’s what to do + a real free option” guide ready NOW, so when the purge hits, you’re the first result they land on.

:brain: Example: A 22-year-old in Manila pre-wrote a “my VPN extension disappeared, help” post targeting that exact phrase, parked it on a free blog, and caught the search spike the week the removals rolled out.

:chart_increasing: Timeline: The window is brutal-short — maybe 2–4 weeks of spiking searches. Move before the purge, not after, or you missed it.

📡 The 30-Second Leak-Test Booth

Teach people the one check that catches a fake in seconds: does your “VPN” actually change your visible location? You point them (or do it for them) at ipleak.net and browserleaks.com — if the VPN’s on but your real city still shows, it’s fake or leaking. Package that as a free “Is your VPN actually working?” test, take tips or upsell the full Autopsy.

:brain: Example: A freelancer in Lagos posts a 40-second phone video doing the leak test live, ends with “DM me to check yours,” turns the free checks into paid cleanups.

:chart_increasing: Timeline: Traffic the same day you post the video. The free-to-paid flip works best while the news is hot — first 6 weeks.

🕳️ The Store-Scanner Watchlist

Here’s the picks-and-shovels play. These fakes all quietly asked for the “proxy” power. So you watch the Chrome Web Store for new extensions requesting that permission and publish a weekly “sketchy new add-ons” watchlist for security-curious people. You’re not fighting the scammers — you’re selling the map of where they’re setting up next. First person with a clean feed owns it.

:brain: Example: A self-taught dev in Kraków runs a free weekly email of “new extensions asking for scary permissions,” built the list off public store data, and small security consultancies pay for the early heads-up. Learn how extension permissions work straight from Google’s own docs.

:chart_increasing: Timeline: First subscribers in ~2 weeks. Real credibility (and paying readers) around month 2–3 once you’ve called a bad one before the news did.

🛠️ Follow-Up Actions
Step Do this now
Audit yourself first Open chrome://extensions, remove anything you don’t remember adding
Get the real tools Proton VPN, 1.1.1.1 — from the official sites, not store search
Learn the leak test Bookmark ipleak.net + browserleaks.com
Understand the danger Read what “proxy” permission lets an add-on do in the Chrome docs
Track the source Follow Socket + BleepingComputer for the next batch

:high_voltage: Quick Hits

If you want to… Do this
:shield: Check you’re not a victim Open chrome://extensions and match IDs to Socket’s list
:magnifying_glass_tilted_left: Test any VPN in 30 sec Run ipleak.net with it on — real city showing = fake
:briefcase: Turn the scare into cash Offer per-laptop “browser autopsies” to local shops
:clipboard: Own a search spot Build the “real vs fake VPN” cheat sheet in your language
:satellite_antenna: Sell the map Publish a weekly watchlist of new “proxy permission” add-ons

The tool you trusted to make you invisible made you the most visible person in the room. Check your extensions tonight — seriously.

1 Like