A large campaign involving 737 free VPN and proxy extensions targeted Russian-speaking users by impersonating trusted brands and silently routing browser traffic through attacker-controlled SOCKS5 infrastructure. Separately, the Chrome extension βAI Sidebar with Deepseek, ChatGPT, Claude, and moreβ resurfaced with a new monetization payload after a prior removal, showing how malicious updates can shift from data theft to affiliate abuse. #ProtonVPN #NordVPN #Surfshark #AdGuardVPN #Browsec #ExpressVPN #CyberGhost #Windscribe #TunnelBear #Cloudflare #Outline #AISidebarwithDeepseekChatGPTClaudeandmore
Keypoints
- 737 VPN and proxy extensions were used to intercept browser traffic.
- The add-ons impersonated 66 well-known privacy and VPN brands.
- Most extensions routed sessions through a single SOCKS5 proxy infrastructure.
- Many extensions were removed from the Chrome Web Store, while hundreds remained active.
- The AI Sidebar extension returned with a new affiliate-link monetization scheme after removal.
Read More: https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html