737 Chrome Extensions Were Caught Hijacking VPN Traffic. Here's How to Check
Robert Moore ·
Listen to this article~5 min
Researchers uncovered 737 malicious Chrome extensions routing traffic through proxies, targeting Russian-speaking users. With 75,486 installs, here's how to check if you're affected.
If you've ever installed a free VPN extension from the Chrome Web Store, this one's for you. Researchers just uncovered a sprawling network of 737 malicious extensions that were quietly intercepting browser traffic and routing it through proxy servers. The worst part? They were targeting everyday people looking for a simple way to bypass regional blocks.
These extensions weren't some fringe operation. They were published across at least 40 different developer accounts, which made them look scattered and semi-legitimate. But in reality, they were all part of one coordinated effort to get between you and your data. And they racked up a staggering 75,486 installs before anyone blew the whistle.
### What Exactly Did These Extensions Do?
Think of it like this: you're driving down a highway, and someone redirects you to a toll road you never agreed to take. That's essentially what these extensions did with your browser traffic. They intercepted the data flowing between your browser and the websites you visited, then sent it through their own proxy infrastructure.
The primary targets were Russian-speaking users trying to access blocked services. If you're in that demographic, you might have unknowingly installed one of these extensions thinking it would help you get around censorship. Instead, you handed over your browsing data to complete strangers.
### The Scale of the Problem
Here's the part that should make you pause: out of the 737 malicious extensions, 274 were found to be impersonating 66 different legitimate tools. That's a lot of fake versions of real software floating around. If you searched for a popular VPN extension and grabbed the first result, there's a decent chance you ended up with one of these fakes.
- 737 total malicious extensions identified
- 40+ developer accounts involved in publishing them
- 75,486 total installs across all extensions
- 274 extensions impersonated 66 legitimate tools
### How to Check If You're Affected
So, how do you know if you're one of the unlucky ones? It's actually pretty simple. Open up your Chrome browser and head to the extensions page. You can do this by typing `chrome://extensions` in the address bar and hitting enter.
Once you're there, look for any VPN or proxy extensions you don't recognize. Pay special attention to ones you installed a while ago and forgot about. If you see anything that looks suspicious, remove it immediately. Then, go ahead and clear your browser cache and cookies just to be safe.
### Why Free VPNs Are Usually a Bad Idea
This whole situation is a reminder that free VPNs come with hidden costs. When a service isn't charging you money, it's often making money off your data instead. That's the business model. Legitimate free VPNs exist, but they're rare and usually have strict data limits.
For anything sensitive—like banking, shopping, or personal communications—you're better off with a paid, reputable VPN service. It might cost you a few bucks a month, but that's a small price to pay for knowing your traffic isn't being rerouted through someone else's servers.
### What to Do Next
If you think you might have installed one of these malicious extensions, don't panic. Here's a quick action plan:
1. Check your installed extensions right now
2. Remove anything you don't recognize or trust
3. Run a full antivirus scan on your computer
4. Change your passwords for critical accounts
5. Consider switching to a paid, well-reviewed VPN
The takeaway here is simple: be careful what you install, even from official stores. Malicious actors are getting smarter and more organized. They're creating fake versions of legitimate tools and making them look convincing. Your best defense is a little skepticism and regular housekeeping of your browser extensions.