Listen to this Post

Introduction
In the ever-growing world of cybersecurity threats, browser extensions have become one of the easiest entry points for attackers to exploit unsuspecting users. The recent investigation into FreeVPN.One, a Chrome extension with over 100,000 installations and a verified badge on the Chrome Web Store, has sent shockwaves across the digital security community. Marketed as a tool for online privacy, it was secretly acting as sophisticated spyware, stealing sensitive user data while hiding under the veil of legitimacy. What makes this case even more alarming is how such a malicious extension managed to maintain a verified status on Google’s official marketplace for months without detection.
The Hidden Threat Behind FreeVPN.One
FreeVPN.One was advertised as a free VPN service, supposedly helping users protect their browsing privacy. Instead, it was quietly capturing screenshots of user activity and transmitting them to remote servers. The extension operated through a two-stage architecture, cleverly disguising its malicious actions. When a webpage loaded, it injected scripts across all sites using broad permissions. After a 1.1-second delay, it triggered a secret command to activate Chrome’s chrome.tabs.captureVisibleTab() API, allowing it to take high-resolution screenshots of whatever was on the user’s screen.
These stolen images often contained banking credentials, private chats, company documents, and even personal photos. Along with screenshots, the extension transmitted device information, IP location data, and browsing identifiers to a suspicious domain, aitd.one/brange.php. To avoid detection, the data was encoded in base64 and later upgraded with AES-256-GCM encryption and RSA key wrapping, making it almost impossible for traditional monitoring tools to identify the theft.
From VPN to Advanced Spyware
Researchers discovered that FreeVPN.One did not begin as malware. In fact, it initially worked as a legitimate VPN extension, gaining user trust over time. The turning point came with a series of updates in 2025:
Version 3.0.3 (April 2025): Introduced <all_urls> permission, allowing access to every single website visited.
Version 3.1.1 (June 2025): Rebranded itself with fake “AI Threat Detection” features while expanding content scripts to all pages.
Version 3.1.3 (July 2025): Began active data collection after registering the aitd.one domain.
Version 3.1.4 (Final Update): Added encryption layers to conceal data theft from network security tools.
This gradual shift from a trusted VPN service to fully operational spyware shows how malicious developers carefully weaponize user trust over time.
Developer’s Dubious Explanation
When confronted, the developer claimed the screenshot functionality was designed for a “Background Scanning” feature meant to detect malicious domains. However, evidence showed that screenshots were taken even on trusted platforms such as Google Photos and Google Sheets. Once pressed for proof of company legitimacy, the developer went silent, leaving behind only a placeholder Wix domain. This silence further confirmed the malicious intent behind the extension.
Larger Implications for Browser Security
This case raises urgent questions about Google’s extension vetting system. If a spyware tool can remain verified on the Chrome Web Store while executing mass surveillance operations, what other malicious tools might be lurking undetected? Browser extensions have become integral to productivity, but they also pose significant risks when abused.
Cybersecurity experts warn that users must treat every extension as a potential risk and install only those from highly reputable developers. Marketplaces like Google’s Web Store must also adopt stricter monitoring practices, including real-time behavioral analysis, to prevent such large-scale data breaches in the future.
What Undercode Say:
The discovery of FreeVPN.One as spyware is more than just another cybersecurity incident; it highlights systemic flaws in trust and oversight. Browser extensions are often granted far-reaching permissions that would never be allowed in standalone apps. By requesting <all_urls> access, an extension gains visibility into every corner of a user’s online life — essentially operating as a window into their digital identity.
The progression of FreeVPN.One shows the strategic patience of malicious actors. By first operating legitimately, the developers built credibility, encouraging users to keep the extension installed. Over time, updates quietly expanded its power until it became a fully weaponized surveillance tool. This type of “Trojan Horse evolution” is becoming more common, where trusted apps slowly morph into threats once they gain a strong user base.
From a technical perspective, the use of AES-256-GCM with RSA key wrapping demonstrates sophistication. Such encryption is typically seen in enterprise-grade secure communications, not browser extensions. This suggests that the attackers wanted to ensure data theft was invisible to intrusion detection systems (IDS) and corporate firewalls, making the spyware suitable for targeting businesses as well as individuals.
The fact that screenshots were exfiltrated is especially concerning. Unlike text-based data theft, screenshots capture everything at once — including session tokens, passwords, private documents, or confidential emails — bypassing many security tools that scan text but cannot interpret images. This makes the attack highly efficient and dangerous.
Another alarming factor is Google’s verified badge failure. Users often assume a verified extension means safety, but this case shows otherwise. Attackers exploited that trust, creating a false sense of legitimacy. Unless Google strengthens its detection mechanisms, similar incidents will continue, especially as attackers realize how easily they can infiltrate official stores.
This also reflects a broader cybersecurity challenge: supply chain trust abuse. Just as compromised updates from legitimate vendors can harm businesses, browser extensions can act as supply chain vectors, delivering malware under trusted branding. The failure to detect such abuse endangers not only individual privacy but also corporate networks that rely on browser-based workflows.
The silence of the developer is equally telling. The excuse of “background scanning” falls apart when applied to services like Google Sheets. No legitimate privacy tool needs to capture screenshots of spreadsheets or personal photos. The refusal to provide company details indicates a deliberate attempt to remain anonymous, making accountability impossible.
Moving forward, both users and marketplaces need to adapt. Users should:
Regularly audit installed extensions.
Avoid tools requesting broad permissions like ``.
Prefer open-source or audited software.
Meanwhile, marketplaces must implement continuous behavior monitoring, not just one-time reviews, to detect when trusted tools turn malicious.
In essence, FreeVPN.One exposes the fragility of digital trust in modern platforms. It is a warning sign that even tools labeled as “privacy protection” may actually be weapons of surveillance.
🔍 Fact Checker Results
✅ Verified: FreeVPN.One was a real Chrome extension with 100,000+ installs.
✅ Confirmed: The extension secretly captured screenshots and transmitted data to remote servers.
❌ False Claim: Developer’s explanation of “background scanning” does not align with observed activity.
📊 Prediction
The exposure of FreeVPN.One will likely push Google and other browser vendors to tighten extension security policies. Expect stricter monitoring of permissions like <all_urls>, real-time behavioral scanning of extensions, and faster takedowns of suspicious updates. At the same time, attackers will adapt, possibly hiding spyware in AI-branded security tools or productivity extensions to appear legitimate. This incident is not an isolated case but the beginning of a new wave of extension-based espionage.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub:
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




