# The VPN That Watches You Back: 737 Chrome Extensions Turned Russian Users Into Proxy Nodes


Free tools promising to bypass Russia's internet blocks were doing something else entirely — funneling user traffic through attacker-controlled infrastructure at scale.


---


## Who Gets Hurt When the Privacy Tool Is the Threat


The pitch writes itself: Russia has blocked half the web. You need a VPN. Here's a free one, right in the Chrome Web Store, one-click install, no account required.


Researchers have now confirmed what security professionals have long suspected about this corner of the extension ecosystem: 737 of these free VPN and proxy tools were operating as malicious proxies themselves, intercepting browser traffic and routing it through infrastructure their developers controlled. The extensions, spread across at least 40 developer accounts in the Chrome Web Store, accumulated 75,486 installs — almost entirely from users who thought they were gaining privacy, not surrendering it.


The targeting was deliberate. These extensions were crafted for Russian-speaking users seeking access to services blocked by the Kremlin's ongoing internet censorship campaign. That's a population with urgent, legitimate need for circumvention tools, limited technical resources to vet what they're installing, and few alternatives to the free tier. In other words: the ideal target for a proxy harvesting operation.


---


## How the Trap Works


The mechanism here isn't novel, but the scale is striking. A proxy extension promises to tunnel your traffic somewhere safer. A malicious one does tunnel your traffic — just to infrastructure the attacker owns, not to some neutral exit node in another country.


What does that mean in practice? The attacker sees your DNS queries. They see the hostnames of sites you visit. Depending on implementation, they may see unencrypted traffic or be positioned to strip TLS in specific scenarios. Beyond passive surveillance, your browser — and your IP address — becomes a node in someone else's proxy network.


That last part is the commercial engine behind many of these operations. Residential proxy networks sell access to real IP addresses, real browsers, real locations, at a premium over datacenter proxies. Advertisers, scrapers, credential stuffers, and fraud rings all pay for them. The users browsing behind these extensions aren't just being surveilled — they're being rented out.


Of the 737 extensions identified, 274 were found to impersonate 66 legitimate services. That's a sophisticated supply chain: study which real VPN brands have name recognition among Russian speakers, clone their icons and descriptions, flood the store with near-identical listings, and collect installs from users who think they're downloading the real thing.


---


## The Chrome Web Store Has a Structural Problem


This isn't a one-off supply chain incident. It's the latest chapter in a years-long failure of extension vetting at scale.


The numbers tell the story. Forty developer accounts. Seven hundred and thirty-seven extensions. Seventy-five thousand installs. None of this should have accumulated without triggering automated detection — yet it did. The Chrome Web Store has improved its review processes over the years, but it has never solved the fundamental tension between frictionless publishing (which developers want) and meaningful security review (which users need).


The 40-account distribution is textbook. Rather than pushing all extensions from a single developer identity that could be flagged and bulk-removed, operators fragment across accounts. When one gets burned, the others keep running. It's the same distribution strategy used by fake review sellers and app farm operators — and it works for the same reason: review systems look for individual bad actors, not coordinated networks of them.


Google has takedown authority and has used it for high-profile cases, but reactive enforcement doesn't protect the 75,000 users who already installed these before researchers flagged them. Nor does it address the structural incentive: the Chrome Web Store is free to publish to, the review bar is low, and the commercial upside of running a residential proxy operation off browser extensions is substantial.


---


## The Censorship-Circumvention Attack Surface


What makes this campaign particularly cynical is the target selection. Russian internet users have faced accelerating censorship pressure since 2022 — Instagram, Facebook, Twitter, independent news sites, and significant chunks of Western commercial services have all been blocked or severely degraded. The demand for working circumvention tools is real, urgent, and not well-served by the mainstream VPN market, which skews toward English-speaking commercial customers.


Into that gap pour free, unvetted extensions. Some are legitimate. Many aren't. And users in this position face a classic security-usability tradeoff with no good answer: the more technically sophisticated verification steps required to confirm a tool is safe, the less accessible it is to the people who need it most.


This isn't unique to Russia. Iranian, Chinese, and Belarusian users face similar ecosystems of fake circumvention tools. The pattern suggests organized operations specifically targeting censored markets — where demand is high, scrutiny is low, and victims have limited recourse.


---


## What You Should Actually Do


If you or anyone you know runs a free VPN or proxy extension in Chrome, the calculus is straightforward:


Audit immediately. Open chrome://extensions/ and review everything installed. Look for extensions with vague permissions descriptions, developer accounts with multiple nearly identical listings, or tools claiming to offer premium features free.


Check permissions carefully. A VPN extension needs network access — but if it's requesting access to read data on all websites, manage your downloads, or access your clipboard, that's a red flag. Legitimate proxy tools don't need most of those.


Prefer paid, named products with audits. Mullvad, ProtonVPN, and similar providers publish independent audits of their software. Free Chrome extensions have no such accountability. The economics of free proxies require monetization somewhere — and user traffic is the obvious answer.


Enterprises should block extension categories by policy. Any organization that hasn't restricted which extension categories employees can install is accepting proxy-node risk. Chrome's ExtensionInstallBlocklist group policy and similar controls exist specifically for this reason.


---


## HackWire Analysis


The 737-extension campaign fits a pattern that's been building for three years: the deliberate exploitation of users with urgent circumvention needs as a residential proxy harvesting vector. What's underreported in coverage of this incident is the sophistication of the targeting model.


These weren't spray-and-pray installs. The attacker chose a population — Russian speakers blocked from Western services — that has structural reasons to install unofficial tools, limited ability to verify legitimacy, and high geographic value to residential proxy buyers. Russian residential IPs are valuable precisely because they're rare in proxy pools; most datacenter proxies are flagged by fraud detection systems, but a real Russian household IP browsing normally is worth money.


This means the operation was almost certainly profitable before it was caught, and the 75,486 install figure is likely understated — these campaigns typically include extensions that were removed before researchers completed their survey.


The deeper issue is what this says about the Chrome Web Store's role as a distribution surface. Microsoft Edge's extension store, Firefox Add-ons, and Safari Extensions all have similar problems at smaller scale. The browser extension model grants privileged access to session data, cookies, and traffic — essentially everything a man-in-the-browser attack needs — and the review gates have never matched that risk level. Until browser vendors treat extension review with the same rigor applied to OS-level driver signing, this attack surface will keep being exploited.


For security teams: treat browser extensions as installed software, not settings. Audit them, inventory them, and restrict them. The free VPN your employee installed at home and then logged into their work browser with is a live threat to your network.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)