Thirty-one Chrome extensions sold as VPNs for specific websites share one codebase that lets their operator change, after installation, which browsing traffic passes through proxy servers, CyberInsider reported on 28 September, citing research by RiskyPlugins. The extensions had about 356,000 combined users. RiskyPlugins disclosed the cluster on 3 and 4 September.
Background
A browser extension that holds Chrome's proxy permission decides where the browser sends its requests. A real VPN encrypts a device's traffic and sends it to a provider the user has chosen. An extension with proxy control can do a different thing: route selected sites through servers that someone else controls [1].
What the report describes
The extensions are aimed at Russian-speaking users who want access to blocked or restricted services, and use names tied to YouTube, Telegram, Instagram, ChatGPT, Netflix and other platforms. The largest, a RuTracker VPN, had 200,000 installations. The report says all 31 request Chrome's proxy control, web authentication provider access and host access to all websites [1].
A remote configuration decides which sites are routed through a proxy, so the operator can change the list without publishing an update. One variant, Total VPN, routes all traffic instead of selected sites [1].
RiskyPlugins linked the collection to three publisher accounts. It says it decoded the extensions' remote configuration on 3 and 4 September and that the listings were still live during its scan on 18 September. A separate tracker still showed 200,000 listed users for the largest extension on 27 September [1].
Implications for Mac users
Chrome extensions run on macOS as they do on other systems, and the report does not limit the cluster to one platform. People who installed one of these tools are the exposed group. Anyone who never installs extensions that ask for proxy control is unaffected by this cluster as reported [1].
Recommendations
- Open chrome://extensions and remove any VPN extension you did not choose deliberately.
- Check each remaining extension’s permissions and remove any that can control the proxy without a clear reason.
- For a VPN, use a provider’s own app rather than a browser add-on that asks for access to all sites.
Relevance to FireAI
FireAI works per app, not per extension. Chrome appears as one app, so FireAI cannot tell an extension's proxy traffic from the browser's own. What it does show is which destinations Chrome connects to, on the world map, and per-app rules can block a server or address once it is known. FireAI does not audit extensions and does not remove them.
Limitations
Researchers could not determine whether the operators intercept data, resell the connections or read encrypted content. The report does not say whether Google has removed the listings, and it leaves open a possible link to Browsec VPN because some server names overlap [1]. The user total is the researchers' figure from their last check.
Try FireAI, by HisnLabs free for 17 days.