Overview
- Koi Security reports the FreeVPN.One Chrome extension silently captures a screenshot about a second after each page loads and sends it to developer-run servers.
- The add-on has over 100,000 installs and still displays Chrome Web Store verification or featured badges despite the reported behavior.
- Recent updates expanded permissions such as tabs and scripting, enabling script injection across all sites, and later releases added obfuscation, according to researchers.
- The developer says the capability is disclosed in its policy and that collected data is encrypted, while researchers cite July policy edits and missing operator details.
- Experts recommend uninstalling the extension, running antivirus scans, and resetting passwords for sites visited while it was installed, with the Chrome listing still available today.