Post

Legitimate Chrome VPN Extension Turns to Browser Spyware

A popular Google-featured browser extension offering a virtual private network (VPN) service recently turned malicious and is now spying on users’ every move online. Researchers from Koi Security detected that FreeVPN.One, a VPN extension with over 100,000 installs on the Chrome Web Store, a ‘Verified’ status and a 3.8/5 rating from 1110 reviews, has been acting as spyware for the past five months. Launched in 2020, FreeVPN.One was a seemingly legitimate Chrome VPN extension until an update to version 3.0.3 of the application in April 2025.

Two updates later, FreeVPN.One is at v3.1.3 on July 17. With this latest version, the extension started silently capturing screenshots of users’ online activity and collecting and exfiltrating sensitive and personal information.

To read the complete article, see: Link to Full Article

This post is licensed under CC BY 4.0 by the author.