Chrome Web Store
1Versions
1Code reviewed

Do not install

Code review: critical

Our reviewer read this extension’s code and confirmed malicious behaviour. 4 security findings documented below. Do not install it. Remove it if you already have it.

What our analysis found

Windscribe VPN — Бесплатный VPN для браузера is rated malicious by Extension Auditor. Our code review reported 4 findings (1 critical, 2 high, 1 medium), led by network interception. It comes from a publisher with 13 extensions and was last updated in July 2026.

Key findings

  • critical· network interception —A single hardcoded proxy at is applied at browser scope ('regular') with only <local> bypassed, so every non-local request's destination host (via) and the full plaintext of any http:// request passes through, and can be modified by, that operator. The extension is branded as Windscribe VPN, whose actual service runs on infrastructure, so this endpoint is not the first-party backend the listing implies and the user has no way to learn who operates it. The privacy policy is a paste rather than a Windscribe document, and the publisher is a gmail address, so there is no accountable party for the traffic being relayed.
  • high· network interception —Once the popup toggle is used, the flag persists in chrome.storage.local and the proxy override is silently re-applied on every browser start without any further user interaction or indication outside the extension popup. This makes the redirection of all browser traffic to the third-party host durable across sessions, so a user who tried the toggle once keeps every subsequent browsing session routed through that operator.
  • high· other —The popup, manifest name and action title all present the product as 'Windscribe VPN', an established commercial VPN brand, while every endpoint in the code (proxy host, install tab, Premium button) belongs to. The 'Получить премиум бесплатно' button and the 'Премиум' tiles are non-functional decoration that exists only to drive the user to that unrelated domain. The deception is what makes the proxy override harmful: users grant whole-browser traffic relay believing it goes to Windscribe.
  • medium· other —On install the extension force-opens an active tab to, the same domain that owns the proxy endpoint. Combined with the Windscribe branding this delivers every new user to an operator-controlled web property under a borrowed identity, which is the monetisation path for the impersonation rather than any VPN functionality.

1-11 sets a browser-wide chrome.proxy fixed_servers rule to with bypassList ['<local>'] only, while the manifest name,:6 title and:12 heading all brand the extension 'Windscribe VPN' - a real commercial VPN whose infrastructure is, not. Routing every destination of a user's browsing to an unaccountable operator under a borrowed brand, plus an install-time tab open to that same domain (:47-53) and a 'Premium' button pointing there (:43-47), is deceptive traffic interception rather than a VPN service. Corroborating: declares ~17 unused layout-* and ~10 btn-* variants of which the page uses only layout-dashboard_tiles and btn-shield, code-level proof of a mass-produced template kit consistent with the 1114-version permhash cluster (38% flagged), and 213 five-star reviews against 332 users is an implausible review rate. Contradicting / unreliable: the chrome-stats permission-clipboard reason is simply wrong for this manifest (no clipboard permission exists), and the ML evidence is only counters (3758 JS bytes, 12 files) - the code confirms the score for entirely different reasons than the model used; the bundled and published manifests match, so there is no manifest-mismatch finding.

Windscribe VPN — Бесплатный VPN для браузера

Windscribe VPN — Бесплатный VPN для браузера

ID: hiddjonniafmibjlbfcpoagjkgliifne

Supported Languages

🇷🇺Russian

Extension Info & Metadata

Status
Active
Version
1.2.0
Size
0.03 MB
Rating
5.0/5
Reviews
214
Users
466
Type
Extension
Updated
Jul 29, 2026
Category
Privacy & security
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
13extensions
4 no longer listed

Publisher Contextual Analysis

Author
hutitar561@gmail.comView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Extensions
13
Active
9
Obsolete
4
Listed
13
Unlisted
0
Users
1,056

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
proxy
Permission
Critical
This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
  • 1 critical
  • 2 high
  • 1 medium

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Браузерный канал. Бесплатное подключение и Премиум.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
1.2.0
Latest
0.03 MBMalicious0
Showing 1 to 1 of 10 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.