A large-scale malicious browser extension campaign has been identified, comprising at least 737 fraudulent VPN extensions for Google Chrome. These extensions, found in the Chrome Web Store and on third-party sites, masquerade as legitimate VPN services from well-known brands like Proton VPN and NordVPN. However, instead of encrypting and securing user traffic, they act as proxies, funneling all of a user's web traffic through a single, centrally-controlled network operated by the attackers. This creates a massive Man-in-the-Middle (MitM) scenario, allowing the operators to intercept, monitor, and potentially modify all data passing through their servers. Users who have installed these extensions are at significant risk of credential theft, financial fraud, and privacy violations.
This campaign exploits user trust in both the Chrome Web Store and popular VPN brands. The threat actor has flooded the ecosystem with hundreds of seemingly distinct extensions that all share the same malicious backend infrastructure.
Attack Method:
In one analyzed batch, 522 of the extensions were found to be using the exact same proxy infrastructure, confirming a highly coordinated operation.
The malicious extensions abuse the proxy permission in the Chrome extension manifest (manifest.json). This permission allows an extension to programmatically set the browser's proxy settings. The extensions are configured to point to a PAC (Proxy Auto-Config) file or directly to the IP address of the attacker's proxy server. This allows them to intercept all web requests made by the user's browser.
Because the attackers control the proxy, they can terminate TLS connections and re-encrypt them with their own certificate, allowing them to view the content of HTTPS traffic. While browsers would typically show a certificate warning, the attackers may be able to suppress this or hope that users click through the warnings.
The potential impact on users is severe:
Given the global user base of Google Chrome, the number of affected individuals could be very large.
No specific extension IDs, domains, or IP addresses were disclosed in the source articles.
For individual users and corporate IT, here's how to look for these extensions:
chrome://extensionschrome://settings/systemUnusual Proxy Trafficnordvpn.com, protonvpn.com), not from the Chrome Web Store or third-party sites.In an enterprise environment, use browser management policies to create an allowlist of approved extensions and block all others.
Educate users on the risks of browser extensions and the importance of vetting them before installation.
Monitor and filter outbound network traffic to block connections to known malicious or unauthorized proxy servers.
Mapped D3FEND Techniques:

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.