Researchers Identified 31 Malicious Chrome Extensions
The extensions posed as VPN tools to hijack user browser traffic through remote proxy servers.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust browser extensions to handle your personal traffic and data securely?
Security analysts have identified a campaign of 31 Russian-language Chrome extensions masquerading as VPN tools. These plugins have compromised browser traffic for 356,000 installations by routing user activity through attacker-controlled proxy infrastructure.
Why it matters
This campaign highlights the persistent risk of browser-based supply chain attacks where extensions are weaponized to intercept data. It underscores the vulnerabilities inherent in browser plugin ecosystems that lack granular control over traffic routing.
The 31 malicious extensions operated by steering traffic through remotely controlled proxy servers. This represents a significant expansion of browser-based interception beyond localized malware, affecting 356,000 active installations.
The players
Risky Plugins
A security research organization that tracks and discloses vulnerabilities in browser-based software and plugin ecosystems.
The details
These malicious extensions function as proxies by modifying browser network settings to steer traffic through attacker-owned servers. A proxy server — an intermediary machine that routes traffic between a client and the internet — allows the operator to intercept or monitor unencrypted web data. The extensions were specifically localized in the Russian language, targeting users seeking VPN tools to change their network identity.
Timeline
September 19, 2026: The security research firm Risky Plugins disclosed the malicious campaign.
The Tech Race
This incident follows the precedent set by previous browser-based interception campaigns that weaponize common utility tools. It highlights an ongoing race between security researchers and malicious actors to monitor and filter the extension marketplace for compromised traffic-routing plugins.
Users should immediately audit their installed browser plugins and remove any unrecognized VPN tools. Those affected should assume that unencrypted web traffic routed through these extensions may have been intercepted by external proxy operators.
The takeaway
Browser extensions retain broad permissions that can be exploited for traffic redirection without a user's explicit consent. Monitor your browser's proxy settings and remove any extensions that were not intentionally installed for verified security needs.
Further reading
For broader trends in browser safety, visit our Cybersecurity section.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you trust browser extensions to handle your personal traffic and data securely?







