<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd" -->

---
title: 737 malicious VPN extensions found in Chrome Web Store,...
description: Socket&#x27;s Threat Research Team discovered 737 malicious free VPN and proxy Chrome extensions across 40+ developer accounts, with 516 still live in the Chrome...
canonical: https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: 737 malicious VPN extensions found in Chrome Web Store, 516 still live | daily.dev
og:description: Socket&#x27;s Threat Research Team discovered 737 malicious free VPN and proxy Chrome extensions across 40+ developer accounts, with 516 still live in the Chrome...
og:url: https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd
og:image: https://api.daily.dev/og/posts/xRztlQrbD.png
og:image:alt: 737 malicious VPN extensions found in Chrome Web Store, 516 still live
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 737 malicious VPN extensions found in Chrome Web Store, 516 still live

**[Collections](https://daily.dev/sources/collections)** · 1 min read · 1 upvotes · 0 comments

## Summary

Socket's Threat Research Team discovered 737 malicious free VPN and proxy Chrome extensions across 40+ developer accounts, with 516 still live in the Chrome Web Store. The extensions impersonate well-known VPN brands like NordVPN and ProtonVPN, silently routing all browser traffic through SOCKS5 proxies on port 1082 controlled by a single Russian operator called 'Myxa VPN.' The extensions bypassed Chrome Web Store review using nine byte-identical fake privacy justification documents and post-approval code substitution. Attribution evidence includes a leaked Windows build path, shared Yandex Metrika analytics, bulk domain registrations, and a Russian business contract. An earlier privacy policy explicitly committed to sharing user data with Russian state authorities. Google has removed 221 extensions, but 516 remain with 58,318 combined installs.

## Content

Socket's Threat Research Team just dropped a report that's worth paying attention to if you've ever installed a

## Questions this post answers

### How did malicious VPN extensions bypass Chrome Web Store review?

The extensions used nine byte-identical fake privacy justification documents falsely claiming they don't transmit external data. After passing review, they introduced malicious behavior via post-approval code substitution, exploiting remote configuration capabilities added after the initial approval. This two-stage approach — clean submission followed by post-approval modification — allowed them to evade the review process entirely.

_Developers shipping or auditing Chrome extensions track supply chain and review-bypass techniques like these on daily.dev._

### What does the malicious Myxa VPN Chrome extension network actually do to browser traffic?

All browser traffic is silently routed through SOCKS5 proxies on port 1082, controlled by a single operator called 'Myxa VPN.' 520 of 522 analyzed extensions pointed to the same proxy infrastructure. 104 of them use DNS-over-HTTPS to resolve proxy IPs, bypassing plaintext DNS queries that security tools might detect. The advertised premium server locations don't actually resolve — the paywall is intentionally non-functional.

_Security engineers monitoring threats to developer tooling find incident breakdowns like this on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#devtools](https://daily.dev/tags/devtools), [#google-chrome](https://daily.dev/tags/google-chrome), [#vpn](https://daily.dev/tags/vpn)

[View this post on daily.dev](https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"737 malicious VPN extensions found in Chrome Web Store, 516 still live","url":"https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd"},"datePublished":"2026-08-12T01:58:20.585Z","dateModified":"2026-08-12T18:57:23.466Z","description":"Socket's Threat Research Team discovered 737 malicious free VPN and proxy Chrome extensions across 40+ developer accounts, with 516 still live in the Chrome...","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,devtools,google-chrome,vpn","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"737 malicious VPN extensions found in Chrome Web Store, 516 still live"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/737-malicious-vpn-extensions-found-in-chrome-web-store-516-still-live-xrztlqrbd#faq","mainEntity":[{"@type":"Question","name":"How did malicious VPN extensions bypass Chrome Web Store review?","acceptedAnswer":{"@type":"Answer","text":"The extensions used nine byte-identical fake privacy justification documents falsely claiming they don't transmit external data. After passing review, they introduced malicious behavior via post-approval code substitution, exploiting remote configuration capabilities added after the initial approval. This two-stage approach — clean submission followed by post-approval modification — allowed them to evade the review process entirely. Developers shipping or auditing Chrome extensions track supply chain and review-bypass techniques like these on daily.dev."}},{"@type":"Question","name":"What does the malicious Myxa VPN Chrome extension network actually do to browser traffic?","acceptedAnswer":{"@type":"Answer","text":"All browser traffic is silently routed through SOCKS5 proxies on port 1082, controlled by a single operator called 'Myxa VPN.' 520 of 522 analyzed extensions pointed to the same proxy infrastructure. 104 of them use DNS-over-HTTPS to resolve proxy IPs, bypassing plaintext DNS queries that security tools might detect. The advertised premium server locations don't actually resolve — the paywall is intentionally non-functional. Security engineers monitoring threats to developer tooling find incident breakdowns like this on daily.dev."}}]}
```

