
Thirty-one Chrome extensions advertised as VPNs for specific websites share code that lets their operator change which browsing traffic passes through proxy servers after installation.
The extensions had roughly 356,000 users combined when researchers at RiskyPlugins last checked.
RiskyPlugins disclosed the cluster after examining extension code and decoding its remote configuration on September 3 and 4. The researchers linked the extensions to three publisher accounts and said the listings were still live during their September 18 scan. The largest, РуТрекер VPN, accounted for 200,000 installs; a separate listing tracker still reported 200,000 users for that extension on September 27.
The extensions are mostly marketed to Russian-speaking users as ways to access services including YouTube, Telegram, Instagram, ChatGPT, Claude, Netflix, and RuTracker. Other listings in the same cluster present themselves as a job application helper, a Telegram photo downloader, and a Wikipedia search tool.
Proxy destinations can change after installation
According to RiskyPlugins, the extensions request Chrome’s proxy and webRequestAuthProvider permissions, along with host access to <all_urls>. They use a proxy auto-configuration (PAC) script to decide which websites should be routed through a proxy. The Total VPN variant routes all browser traffic through the proxy rather than limiting it to a list of destinations.
The list of proxy servers is downloaded after installation instead of being fixed in the extension package. RiskyPlugins found redundant sources for that list on GitHub Pages, Blogspot, a Google Doc, and a Telegram channel. Its contents were encoded using base64 and a Caesar shift, which obscures the configuration without providing meaningful protection. The decoded data included proxy credentials with monthly expiration dates. The extensions also advertise a VIP subscription priced at 299 rubles.
This setup gives whoever controls the remote configuration the ability to change proxy destinations without publishing an extension update. Routing traffic through an unfamiliar proxy can expose browsing destinations and unencrypted data to its operator. The report does not establish that the operators stole data, sold users’ connections, or intercepted encrypted page contents.
RiskyPlugins noted that three fallback proxy hostnames matched names associated with Browsec VPN premium servers. The researchers could not confirm that these extensions could connect to those servers and did not attribute the cluster to Browsec or identify its operator.
Users can check chrome://extensions for the listed add-ons and remove any matching the list shared in the RiskyPlugins report.







Leave a Reply