Chrome Web Store
1Versions
1Code reviewed

Caution required

Suspicious in code review

Our reviewer found behaviour consistent with malware, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Windscribe VPN is rated caution by Extension Auditor. Our code review reported 2 findings (1 critical, 1 high), led by network interception. It comes from a publisher with 13 extensions and was last updated in July 2026.

Key findings

  • critical· network interception —All browser traffic is forced through a single hard-coded proxy, (:10), with "<local>" as the only bypass entry, and the setting is re-applied on every browser startup (:126-137). That host belongs to neither Windscribe nor any domain referenced by the publisher, and the CWS listing declares no data collection, so an unidentified operator silently receives every hostname the browser requests and can read, block or inject content into all plaintext HTTP. HTTPS page bodies stay encrypted (there is no certificate install and no webRequest hook), but the full browsing-destination stream is undisclosed third-party collection and the HTTP path is fully interceptable.
  • high· phishing —The extension presents itself as "Windscribe VPN", an established commercial VPN brand, but is published by hewabivid402@ and sends traffic to, a domain with no relationship to Windscribe; the publisher's own privacy policy link is a page titled "Browsec-VPN", yet another unrelated brand, and the listing's privacy policy is a paste. The THEME value "batch-09-v-d-star" together with the unused variant classes retained in (body.v-a..v-e,, frame-*, ten dial-button shapes) shows the package was emitted by a template generator that mass-produces interchangeable branded skins. Users install this believing they are getting an audited VPN from a named vendor and instead hand their entire browsing stream to an anonymous operator; the install-time tab to (:103-124) and the "get premium for free" button (:184-188) drive them to that operator's landing page.

The extension counterfeits the Windscribe brand (:2 VPN_NAME "Windscribe VPN") while routing 100% of browser traffic to an unrelated anonymous host, (:10, applied in:24-49 as mode "fixed_servers" with only "<local>" bypassed) with no account, no authentication and no CWS-declared data collection; the publisher-level privacy policy is a page titled "Browsec-VPN", a third unrelated brand, and THEME "batch-09-v-d-star" plus the v-a..v-e / fx-* / dial-shape variant scaffolding left in show this is one output of a template generator. The code corroborates the ML score for the right reason: the proxy itself is the data channel, so the operator receives every CONNECT hostname the user visits and can read, block or inject into all plaintext HTTP, and no disclosure authorizes that. Contradicting or weak signals: there is no, eval, remote code loading or obfuscation in the bundle (js_innerhtml=1 is:107 clearing a list with innerHTML = ""), the bundled and published manifests match exactly so there is no manifest mismatch, and chrome-stats' "permission-clipboard" reason is simply wrong since neither manifest requests clipboard access; the publisher's malicious leave-one-out record, the malext feed note, the 38% malicious permhash cluster and 247 reviews against 226 users are corroboration layered on top of the code evidence, not its basis.

Windscribe VPN

Windscribe VPN Chrome extension security report

ID: paifkghgecedjhpiffccboiopabfkilj

Supported Languages

🇷🇺Russian

Extension Info & Metadata

Status
Active
Version
1.0.0
Size
0.06 MB
Rating
5.0/5
Reviews
247
Users
226
Type
Extension
Updated
Jul 10, 2026
Category
Privacy & security
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
13extensions
8 no longer listed

Publisher Contextual Analysis

Author
hewabivid402@gmail.com
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Extensions
13
Active
5
Obsolete
8
Listed
13
Unlisted
0
Users
1,968

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
proxy
Permission
Critical
This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
  • 1 critical
  • 1 high

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Бесплатный VPN для браузера и популярных сервисов

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
1.0.0
Latest
0.06 MBCaution0
ee57a8c2b55c8a8bcf5277da8b935f31a645ecf20ada7775b72c34cbe008b598
Showing 1 to 1 of 10 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.