Is VPN Proxy Master: Change IP for Chrome safe?
VPN Proxy Master is medium risk. The extension hardcodes a username/password authenticating every user's VPN connection: 'testuser1'/'e4b72b531a2d10900519', plaintext in the JS bundle. One set for everyone lets anyone extracting it use the VPN free or route traffic as you.
Who publishes ithttps://www.vpnproxymaster.com - no other listings under this identity
https://www.vpnproxymaster.com - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Hardcoded shared proxy credentials embedded in extension source code
The extension hardcodes a username/password authenticating every user's VPN connection: 'testuser1'/'e4b72b531a2d10900519', plaintext in the JS bundle.
One set for everyone lets anyone extracting it use the VPN free or route traffic as you.
You activate the VPN, which routes your browser traffic through the extension's proxy server.
When the proxy issues an auth challenge, the extension responds with one hardcoded username/password shared across all users, readable in plaintext in the extension's JavaScript.
The onAuthRequired listener fires for any URL matching <all_urls>, providing the same static credentials regardless of which user is logged in.
Hardcoded credentials in the onAuthRequired handler
chrome.webRequest.onAuthRequired.addListener(
(request, callback) => {
if (!callback) return;
if (request.isProxy === true) {
// Same static credentials for every user, in plaintext
callback({
authCredentials: {
username: "testuser1",
password: "e4b72b531a2d10900519"
}
});
} else {
callback({ cancel: true });
}
},
{ urls: ["<all_urls>"] },
["responseHeaders", "asyncBlocking"]
);| Field | Value | Why it matters | |
|---|---|---|---|
Proxy username | testuser1 | The shared account name sent to the VPN proxy on every authentication challenge, for all users. | |
Proxy password | e4b72b531a2d10900519 | The plaintext password embedded in the extension source, identical for all 100,000 users. |
Because the username and password are identical for every installation, extracting them from the extension source (a few seconds with a text editor or browser devtools) gives anyone access to the same proxy infrastructure. The extension developer cannot revoke a single user's access without rotating credentials for all 100,000 users simultaneously, since there is no per-user token or session identifier in the auth flow.
What it can do
Permissions this extension asks for, as declared in version 1.4.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on vpnproxymaster.com
https://vpnproxymaster.com/*
Read and change your data on www.google.com
https://www.google.com/*
Read and change your data on 301.flashpull.com
https://301.flashpull.com/*
Read and change your data on 301.fastwalk.net
http://301.fastwalk.net/*
Read and change your data on www.google-analytics.com
https://www.google-analytics.com/*
Read and change your data on every site you visit
*://*/*
Route all of your browsing through a server of its choosing
proxy
Store an unlimited amount of data in your browser
unlimitedStorage
Show you desktop notifications
notifications
Store data in your browser
storage
Watch every request your browser makes
webRequest