HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Hundreds of Fake Chrome VPN Extensions Route Traffic Through Malicious Proxy, Exposing Browsers

Researchers uncovered 737 Chrome extensions that impersonated well‑known VPN brands and forced all browser traffic through attacker‑operated SOCKS5 proxies, potentially exposing browsing data. The campaign highlights the need for strict access‑control policies and continuous monitoring of third‑party software in SOC 2‑ready environments.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Hundreds of Fake Chrome VPN Extensions Route Traffic Through a Malicious Proxy

What Happened — Researchers identified 737 Chrome Web Store extensions that masqueraded as popular VPN services (e.g., Proton VPN, NordVPN, ExpressVPN). The extensions forced all browser traffic through attacker‑operated SOCKS5 proxies, allowing the operator to read TLS SNI values, source IPs, and any unencrypted HTTP payloads. The campaign attracted roughly 75 000 downloads, primarily from users seeking to bypass Russian censorship.

Why It Matters for Compliance & Audit Readiness

  • The scenario exemplifies a loss of access control over client‑side software, a core SOC 2 CC6.1 (Logical Access) requirement.
  • Continuous monitoring of third‑party applications and evidence of policy enforcement are essential to demonstrate due diligence in an audit.
  • Security‑awareness training that teaches users to verify approved extensions directly supports the “Security Awareness” control (CC7.1).

Who Is Affected — SaaS providers, cloud‑infrastructure firms, and any organization whose employees use Chrome browsers for business tasks; especially high‑risk sectors such as finance, healthcare, and government that rely on VPNs for remote access.

Recommended Actions

  • Conduct an inventory of installed browser extensions and cross‑reference against an approved‑software list.
  • Enforce a policy that blocks installation of unvetted extensions and logs any proxy‑configuration changes.
  • Deploy network‑traffic monitoring to detect anomalous outbound proxy connections.
  • Update security‑awareness curricula to include examples of malicious extensions and how to verify publisher authenticity.

Source: BleepingComputer

Technical Notes — The extensions used a shared analytics account and 40 publisher accounts to evade detection. Traffic was routed through SOCKS5 proxies on port 1082; some extensions resolved proxy hostnames via Cloudflare or Google DoH to hide the operator’s domain. No direct data breach was reported, but the proxy position enables full visibility of browsing activity and any plaintext data. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →