Fake Proton and Amnezia are still on the Chrome Web Store
Kush Pandya found 274 Chrome extensions wearing other people's VPN brands. They set a SOCKS5 hop on port 1082 for a shop called Myxa.
On 11 August Kush Pandya at Socket walked 737 Chrome VPN listings and found 274 of them wearing someone else's brand. Proton, Nord, Amnezia, AntiZapret, Cloudflare's 1.1.1.1. AmneziaVPN had 22 copies on its own. The packages set a SOCKS5 hop on port 1082 for a Russian shop called Myxa.
Socket retrieved 522 of those packages. In 520, the Connect button writes a fixed_servers config through chrome.proxy.settings: scheme socks5, port 1082, bypass list limited to loopback. Every tab goes through a node the operator chose. 497 of the packages asked for proxy and nothing else.
SOCKS5 as shipped here adds no tunnel encryption. HTTPS covers the payload. The relay sees the destination, the TLS SNI, the client IP, and anything sent in clear HTTP. Proton repeated the Socket numbers today. The listings are a commercial farm.
Fourteen nodes on vpnmyxa[.]site
The live Myxa listing sets SOCKS5 on port 1082 against 14 hardcoded hosts on *.vpnmyxa[.]site. The store copy already says "SOCKS5". Socket's 75,486 "installs" are a sum of Chrome display buckets. The 516 listed / 221 removed split is Socket's count when they collected the corpus.
The issue is that an innocuous brand search for Proton, Amnezia, AntiZapret, Myxa, or Муха returns lookalikes. Two other Socket IDs (ilbpme… and hfanmg…) come back "item not available". But the Myxa listing is up. Google has taken packages down before without touching the publisher accounts. Socket watched 14 of Palo Alto's 15 live IDs vanish in seven weeks while those 15 accounts kept 250 extensions. A developer account costs five dollars.
A fake shop
Socket tied the farm to Myxa, which is Russian for flying. The popup in 360 analysed packages names the supplier. Russian consumer law wants a public offer page, an оферта, that names the contractor. The one at myxavpn[.]pro/oferta/ lists a self-employed person, INN 402809132213, an active tax registration, but no legal name.
Almas Raza published 18 extension IDs on 4 June: one unnamed actor, 15 SOCKS5 proxies. Palo Alto left Myxa off the page.
Nine packages from nine accounts shipped the same reviewer justification. 49 extensions grew a remote-configuration layer after Google had approved a thinner build. One staff manual told employees to put only a DoH-resolved IP in chrome.proxy.settings. 104 of the 522 analysed packages do that. Socket resolved 200 premium hostnames on 40 apex domains and got NXDOMAIN on every one. 690 of 734 listings in the source set used a Cyrillic name, a Cyrillic description, or a blocked-service name.
The shop advertises a VLESS product as well. Socket recovered VLESS-REALITY configs from third-party aggregators. The store listings install the SOCKS5 hop.
Where to find the real one
Install one of these and the browser is on a SOCKS5 hop run by a shop you cannot identify. HTTPS bodies stay unreadable. Destinations, SNI, the client IP, and any HTTP you typed are visible to whoever operates port 1082. Nobody has shown that the operator logged any of it. Treat that window of browser history as observed by a third party. Change credentials submitted over HTTP in that browser.
Open chrome://extensions and remove any VPN or proxy add-on that did not come from the vendor's own site. Chrome's remove-an-extension page is enough. Then open chrome://settings/system. If a proxy is still set, switch it back to your system's settings.
The Myxa listing we checked this evening is still live: aaeiefggdeljohngedhpmgidkjcdoebb. Socket's 11 August report has the rest of the IDs.
Official sites only: Proton, Amnezia, Nord, Express, Surfshark. Proton's own Chrome add-on is published by Proton AG, ID jplgfhpmjnbigmhklmmbgecoobifkmpa. A store search for the brand is how the fakes get found.