If I were evil, I don't implement proxy feature on open Linux VPN client that geeks use, but just implement on closed Windows/Android client. Traffic monitoring is better.
I didn't even read the medium article, only the first one. That's what I quoted from. I agree, investigating traffic would be an excellent idea, but I don't intend on putting my credit card into nord's sketchy site (they apparently don't accept paypal)
If they're truly hijacking end user clients, why don't you point to the section of their open source client that's responsible for that?
https://github.com/NordSecurity/nordvpn-linux
Easy enough to prove.