Malicious Chrome and Firefox VPN Extensions Add Clipboard Stealers Through Updates

Summary
Socket researchers found Chrome and Firefox VPN Go extensions added clipboard-stealing code in later versions, sending copied data to hardcoded servers. The extensions were reported to Google and Mozilla for review.
Key points
- The Chrome extension added confirmed clipboard theft in versions 1.1–1.3; the Firefox extension added it in versions 1.3.3–1.3.4.
- The extensions polled the clipboard, split new copied text into chunks, and exfiltrated it over HTTP to hardcoded servers.
- Copied passwords, MFA codes, API keys, tokens, and other secrets may have been exposed.
- The Chrome and Firefox versions shared exfiltration infrastructure; observed IPs were 178[.]236[.]252[.]133, 178[.]236[.]252[.]161, and 77[.]91[.]123[.]187.
- Both extensions also provided proxy functionality, which gave them a plausible VPN purpose while clipboard monitoring ran in the background.
- Socket reported the extensions to Google and Mozilla. Users are advised to remove them and treat secrets copied while they were installed as exposed.
Article Details
- Attack Vectors
- Browser extensions marketed as free VPNs introduced clipboard theft through staged updates: Chrome versions 1.1–1.3 and Firefox versions 1.3.3–1.3.4 were confirmed malicious.
- The Chrome extension added clipboardRead permission and a content script running on all websites at document_start. It polled the clipboard every 500 milliseconds and forwarded copied text to its background service worker.
- The Firefox extension read clipboard contents directly from its background script every 1.5 seconds.
- Both implementations skipped duplicate clipboard values, split newly copied text into approximately 1,000-character chunks, assigned session identifiers, and transmitted chunks through HTTP GET requests with uid, part, total, and data query parameters.
- Functional proxy configuration and misleading no-data-collection claims provided cover for clipboard theft. Static analysis showed that the extensions could route browser traffic through threat actor-supplied infrastructure; researchers did not dynamically validate the proxy service.
- Defensive Notes
- Remove the identified malicious VPN extensions from Chrome and Firefox.
- Treat secrets copied while the extensions were active as exposed, including passwords, API keys, access tokens, cloud credentials, MFA recovery codes, and cryptocurrency recovery material.
- Inventory browser extensions across managed endpoints and prioritize review of extensions requesting clipboard access, proxy control, tab access, webRequest-related permissions, or access to all websites.
- Hunt for outbound HTTP requests to the reported clipboard-exfiltration endpoints, particularly requests containing uid, part, total, and data query parameters.
- Restrict installation to approved extension IDs, enforce browser management policies, and review permission changes before allowing updates.
- Investigate newly added clipboardRead permissions or content scripts running on all websites when those capabilities are unnecessary for the extension's stated purpose.
- Socket reported both extensions to Google and Mozilla for review and removal; the article does not confirm removal.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
info@vpngogmail[.]com | Contact email in the malicious extensions' misleading privacy policy and explicitly included in the article's indicators. | |
zegivati83@gmail[.]com | Developer registration email listed for the malicious Chrome extension and explicitly included in the article's indicators. | |
| IPV4 | 178[.]236[.]252[.]133 | Threat actor-controlled clipboard-exfiltration and proxy-location infrastructure used by Chrome versions 1.1 and 1.2. |
| IPV4 | 178[.]236[.]252[.]161 | Threat actor-controlled clipboard-exfiltration and proxy-location infrastructure used by Firefox 1.3.3. |
| IPV4 | 77[.]91[.]123[.]187 | Shared threat actor-controlled clipboard-exfiltration and proxy-location infrastructure used by Chrome 1.3 and Firefox 1.3.4. |
| SHA256 | 2fe9c41901045013ba28ccb9af5870f9aef4f1ffd1e717cd5e0189ffdbe7fca2 | SHA256 of the confirmed malicious Firefox XPI version 1.3.4. |
| SHA256 | 43dc5b1d4c73d5ed9f4f7f561830079896eeb533a7c21bc577e4e267d5a3aa56 | SHA256 of the confirmed malicious Chrome CRX version 1.1. |
| SHA256 | 72fc06a8b03720f4a64744eecd5b3f658ad880bdb327c0c465c7bdc66b14a8d2 | SHA256 of the confirmed malicious Chrome CRX version 1.3. |
| SHA256 | b3b63970833b3379ecec2d3ef8fea328fef8dd1c1574b1bcdfebad5bdce9280c | SHA256 of the confirmed malicious Chrome CRX version 1.2. |
| SHA256 | fbbdf4bc490ad7b28953630c1707aa68b89d319b9b735f3d8563320b81b21a97 | SHA256 of the confirmed malicious Firefox XPI version 1.3.3. |
| URL | hxxp[:]//178[.]236[.]252[.]133/html/continue[.]php | Clipboard-exfiltration URL shown in the Chrome background-script code for versions 1.1 and 1.2. |
| URL | hxxp[:]//178[.]236[.]252[.]133/locations | Threat actor-controlled proxy-location retrieval endpoint used by Chrome versions 1.1 and 1.2. |
| URL | hxxp[:]//178[.]236[.]252[.]161/html/continue[.]php | Clipboard-exfiltration endpoint used by Firefox 1.3.3. |
| URL | hxxp[:]//178[.]236[.]252[.]161/locations | Threat actor-controlled proxy-location retrieval endpoint used by Firefox 1.3.3. |
| URL | hxxp[:]//77[.]91[.]123[.]187/html/continue[.]php | Clipboard-exfiltration URL shown in the Chrome 1.3 background-script code. |
| URL | hxxp[:]//77[.]91[.]123[.]187/locations | Threat actor-controlled proxy-location retrieval endpoint used by Chrome 1.3 and Firefox 1.3.4. |
| URL | hxxps[:]//telegra[.]ph/Privacy-Policy-12-11-127 | Specific privacy-policy resource used by the malicious extensions to make misleading claims that no personal or user data was collected. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe Chrome script used meaningless variable names, escaped property strings, and arithmetic constants; Firefox reconstructed its exfiltration URL from arithmetic fragments.T1036 · MasqueradingThe extensions presented themselves as privacy-protecting free VPNs and claimed not to collect user data while secretly stealing clipboard contents.T1041 · Exfiltration Over C2 ChannelClipboard data was transmitted to threat actor-controlled endpoints in the data query parameter, with session and chunk parameters supporting reassembly.T1059.007 · JavaScriptJavaScript content and background scripts implemented clipboard polling, chunking, runtime messaging, and HTTP exfiltration.T1071.001 · Web ProtocolsThe extensions sent clipboard chunks to hardcoded infrastructure using HTTP GET requests.T1115 · Clipboard DataThe extensions repeatedly called navigator.clipboard.readText to collect newly copied text.T1176.001 · Browser ExtensionsChrome and Firefox extensions used browser permissions and extension scripts to collect and exfiltrate clipboard contents.T1195.002 · Compromise Software Supply ChainPreviously analyzed proxy-only extension versions gained malicious clipboard-exfiltration functionality through staged updates.T1204 · User ExecutionThe malicious extensions were presented as free VPN tools to encourage users to install and retain them.
Malware
Free VPN by VPN GOThe Firefox listing for Free VPN by VPN GO uses the same privacy-focused positioning, describing the extension as a free VPN for secure and unrestricted browsing. Yet its required permissions include clipboard access,VPN Go: Free VPNSocket’s Threat Research Team analyzed two browser extensions operating under the VPN Go: Free VPN branding, one listed on the Chrome Web Store and another listed on Mozilla’s Firefox Add-ons marketplace. At the time of
Vendors
GoogleWe have reported both extensions to Google and Mozilla for review and removal.Mozillaoperating under the VPN Go: Free VPN branding, one listed on the Chrome Web Store and another listed on Mozilla’s Firefox Add-ons marketplace. At the time of writing, the Chrome extension listed 146 users, while the
Products
Chrome Web Storeanalyzed two browser extensions operating under the VPN Go: Free VPN branding, one listed on the Chrome Web Store and another listed on Mozilla’s Firefox Add-ons marketplace. At the time of writing, the ChromeFirefox Add-onsthe VPN Go: Free VPN branding, one listed on the Chrome Web Store and another listed on Mozilla’s Firefox Add-ons marketplace. At the time of writing, the Chrome extension listed 146 users, while the FirefoxGoogle ChromeMalicious Chrome and Firefox extensions posing as free VPNs added a clipboard stealer through staged updates, exfiltrating copied data to hardcoded threat actor-controlled infrastructure.Mozilla FirefoxMalicious Chrome and Firefox extensions posing as free VPNs added a clipboard stealer through staged updates, exfiltrating copied data to hardcoded threat actor-controlled infrastructure.