2026-anon-vpn-ai-deepseek
findings extracted from this paper
-
A code-level audit of 737 Chrome VPN and proxy browser extensions found that 520 of 522 sampled packages routed all non-loopback browsing traffic to a single shared SOCKS5 infrastructure; 274 of the 737 impersonated 66 known VPN or privacy brands across at least 40 developer accounts, and 516 of the identified extensions remained live in the Chrome Web Store at the time of data collection.
-
Researchers replayed opaque 'reasoning block' objects from 6,708 publicly posted LLM agent interaction traces against weaker models from the same AI provider, decoding 315,320 blocks and recovering 367 personally identifiable information items and 182 credentials; the attack demonstrates that scrubbing human-readable text from shared agent logs does not prevent leakage of secrets embedded in provider-internal API state objects.
-
Malicious VPN browser extensions using chrome.proxy.settings route all browser requests through an operator-controlled SOCKS5 proxy, giving that operator direct visibility into source IP, connection destinations, TLS SNI hints, and cleartext HTTP content. For HTTPS destinations the payload is not readable, but connection metadata, access patterns, and DNS queries remain exposed at the proxy layer regardless of in-tunnel encryption.
-
Chrome Web Store metrics—including cumulative installation display counts totaling 75,486, five-star ratings, and brand-similar icons—provided no reliable signal of proxy operator trustworthiness among the 737 identified malicious VPN extensions; 516 remained listed throughout the study period despite routing traffic to a shared centralized infrastructure.