Skip to content
Live newsroom 40 readers online
Wednesday, August 26, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingKhan v Cunningham: Shock poll shows Reform in pole position to challenge Labour in London mayor race
Share Suggestions AVOID GOOGL Stage 4 (Conv: 3/5 | Size: 10%)

Hundreds of Fake VPNs Are Flooding the Chrome Web Store

I often tell people to think of VPNs like kitchen funnels. Instead of pouring your network traffic directly into the web and spilling your metadata everywhere, you push it down a narrow tube of encryption. You point your connection exactly where it needs to go without leaking all over the place. Of course, the assumption in […]

By deepak · August 20, 2026 · 4 min read

I often tell people to think of VPNs like kitchen funnels. Instead of pouring your network traffic directly into the web and spilling your metadata everywhere, you push it down a narrow tube of encryption. You point your connection exactly where it needs to go without leaking all over the place. Of course, the assumption in such an arrangement is that you trust your VPN, which controls the flow of traffic from your device to the web. But if the VPN itself is a honeypot for attackers to pry away your data, you’ve just traded several possible security risks for one guaranteed security breach. 

According to the team at Socket, that’s what’s been happening with over seven hundred fake VPN apps listed on the Chrome Web Store. Many of these extensions are free, some are paid, and some even pretend to be from trusted cybersecurity providers to lure users into handing over unrestricted access to their network and browser. This weekend, I dug through Socket’s report to find out exactly what was going on with these apps and how they managed to clear Web Store moderation without getting flagged by Google. I’ll share what I found and offer some tips to help you avoid these fake VPNs. 

In short, Socket’s threat research team analyzed 737 suspicious Chrome extensions that claim to offer VPN and SOCKS5 proxy servers to protect your online privacy. They uncovered paid apps selling access to VPN servers that do not exist, extensions that hijack your proxy to track online activity, and several attempts to impersonate trusted VPN service providers like NordVPN and Surfshark.

Socket is a cybersecurity platform with its own GitHub extension, firewall, and CLI to help developers analyze AI-written code for malicious behavior. When they looked into these Chrome extensions, they found that they were all published by a total of 40 developer accounts and had racked up 75,486 installs from users on the Chrome Web Store. 

Of the 737 suspicious extensions they analyzed, Socket’s team performed a detailed analysis of the code in 525 of them. In total, these extensions amounted to 58,318 active Chrome installs at the time. As for the other 212, they were already taken off the Web Store before Socket could take a look at them. But the researchers found a number of issues right away in the extensions they did analyze, including: 

274 out of 525 extensions plagiarised the branding and logo of one among 66 reputed VPN platforms, including Proton VPN, Surfshark, NordVPN, ExpressVPN, CyberGhost, and TunnelBear. 

Two extensions specifically impersonated AmneziaVPN and AntiZapret, which are often used to get around internet censorship and surveillance. 

Each extension pointed to a fixed SOCKS5 proxy without split tunneling or per-site controls, meaning that all your online activity would get routed through the same server once the extension was installed. 

104 extensions using documented DNS-over-HTTPS evasion techniques to get around Chrome’s blocklists by spoofing their DNS record. 

Many of these VPNs advertise a paid tier with private VPN servers in Japan, Singapore, Canada, Australia, and Turkey. But these servers do not exist, because their hostnames did not resolve when Socket ran a DNS lookup against them. 

With the premium VPN subscriptions, there was no license verification happening internally to detect if the user had actually paid for a subscription. This is not normal for any web-based app or platform that offers a paid tier. 

One of these extensions, Burёnka VPN, does not route traffic through any servers at all. It’s just a fake UI pretending to be a real app. 

Another extension contains a file with a plaintext comment that simply reads, “If Chrome Web Store rejects this because of automatically opening links, we can replace it with a notification offering to go to the Telegram bot.” This shows that the developers know that their app violates Web Store policy, but intend to evade reviews instead of fixing the issue. 

I’ve repeatedly found that the best laid cyber attacks aren’t necessarily the most sophisticated. 

Just so, none of these extensions are particularly difficult to flag in a thorough code review. They got past Chrome’s defenses because they spent a lot of time studying Web Store review processes, possibly learning to evade rejections through repeated trial and error. Many of these developers have already had their other extensions removed by Chrome following a similar report from Palo Alto Networks in June, but they immediately went on to publish new extensions using the same playbook. 

Source: Read the original article on lifehacker.com