Bottom line: Security teams should investigate all 737 Chrome VPN extensions for potential proxy routing.
What's happening: The affected extensions, published across at least 40 Chrome Web Store developers' accounts, were created by Russian developers and primarily targeted users in Russia, Ukraine, and Belarus.
What to do: CISOs should review Chrome Web Store extensions and check for any suspicious activity using tools like Google's Transparency Reports and/or third-party browser extensions like uBlock Origin.