Affected Systems

Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users. Over 500 extensions still active on Chrome Web Store as of reporting.

Exploitation Status

Active campaign. 737 malicious extensions deployed across 40 publisher accounts. Approximately 75,000 installations confirmed. Over 500 extensions remain live on Chrome Web Store despite Google removing 200+. Campaign actively routing user traffic through attacker-controlled SOCKS5 proxies.

Business Impact

All browser traffic from affected users is routed through attacker-controlled SOCKS5 proxies on port 1082, enabling interception of destination URLs, TLS SNI values, source IPs, and plaintext HTTP request bodies. Attackers can monitor browsing activity, capture credentials sent over HTTP, and potentially perform man-in-the-middle attacks. 104 extensions use DNS-over-HTTPS to hide proxy infrastructure. Campaign also includes subscription fraud targeting users seeking VPN services. Corporate users installing these extensions expose internal browsing patterns and potentially sensitive data.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Cross-reference installed Chrome extensions against Socket's published list of malicious extension IDs and remove any matches immediately
  • Verify Chrome proxy settings are set to 'Direct' or corporate-approved values (chrome://settings/system) on all managed endpoints
  • Block installation of Chrome extensions from unverified publishers via Chrome Enterprise policy (ExtensionInstallBlocklist) and enforce allowlist-only approach
  • Review proxy logs and DNS queries for connections to SOCKS5 proxies on port 1082 and DNS-over-HTTPS requests to Cloudflare/Google resolvers from unexpected sources
  • Deploy endpoint detection to alert on Chrome extension installations and changes to browser proxy configuration settings