Independent Reviews
Back to VPN Security News
VPN PrivacyPublished 26 Jul 20266 min read3 sources

Free VPN Extensions Caught Stealing Clipboard Data: What to Check Now

Socket researchers found Chrome and Firefox extensions posing as free VPNs that added clipboard-stealing code through updates, while CyberInsider later amplified the warning for browser users.

Quick takeaways

  • Socket says two extensions branded around VPN Go added clipboard-stealing behaviour after earlier proxy-style versions appeared more benign.
  • Clipboard access can expose copied passwords, MFA codes, API keys, crypto wallet details, recovery phrases and other secrets.
  • A trustworthy VPN app can protect network traffic, but a malicious browser extension sits inside the browser and can undermine privacy directly.

What happened?

Socket's Threat Research Team analysed Chrome and Firefox browser extensions using VPN Go branding and found malicious updates that read clipboard contents and sent copied text to attacker-controlled infrastructure. The Chrome extension was listed as VPN Go: Free VPN, while the Firefox add-on used Free VPN by VPN GO branding.

The researchers said the extensions retained working proxy or VPN-like functionality, which could make them appear legitimate. CyberInsider later republished the warning for browser users, stressing that copied clipboard data may include passwords, financial details, two-factor codes and cryptocurrency information.

Why it matters

Clipboard theft is dangerous because it targets ordinary habits. People copy passwords from managers, paste MFA codes, move API keys, copy recovery phrases, or copy account numbers while assuming the clipboard is temporary and local.

A browser extension does not need to break encryption if the user grants it powerful permissions. Socket said the malicious code read copied values on a timer, skipped duplicates, split longer copied text into chunks and transmitted the data out. That turns a tool marketed as privacy protection into a direct privacy risk.

What you can do now

Open Chrome, Firefox and any Chromium-based browsers you use, then review installed VPN or proxy extensions. Remove anything you do not recognise, no longer use, or cannot verify from a reputable developer. If you had VPN Go: Free VPN or Free VPN by VPN GO installed, treat sensitive data copied while it was active as potentially exposed.

Rotate passwords copied during that period, revoke exposed API or OAuth tokens, replace cloud keys, check important accounts for suspicious sessions, and take extra care with cryptocurrency recovery phrases or wallet addresses. For future installs, prefer reputable full-device VPN apps over obscure free browser extensions, and be suspicious when an extension asks for clipboard access, access to every website, or broad proxy control without a clear need.

Where a VPN helps — and where it does not

A reputable VPN can still help on networks you do not trust by encrypting traffic between your device and the VPN provider and reducing what a hotel, café, airport or workplace guest network can see. That is useful connection privacy.

A VPN does not make a malicious browser extension safe. If an extension can read data inside your browser, it may see secrets before they ever travel over the network. This is also why free VPN risk checks should include ownership, permissions, logging claims, store history and whether the product is a browser extension or a full-device VPN app.

VPN Rocks view

The lesson is not that every free tool is automatically malware, but that a privacy product deserves extra scrutiny when it runs inside your browser. The more sensitive the permission, the higher the trust bar should be.

If you are choosing a VPN, start with the provider's business model, independent audits, app permissions and reputation. A paid, audited VPN from a known provider is usually easier to evaluate than a free browser add-on with broad access and little accountability.

Sources and further reading

VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.

Useful next steps