NEWS

Poper Blocker: Chrome Web Store 'Ad Blocker' Caught Spying on Millions

A Chrome Web Store ad blocker with 2 million-plus users and a Google Featured badge secretly exfiltrates browsing history, screenshots, and AI chats.

Dylan H.

News Desk

September 29, 2026
8 min read
Poper Blocker: Chrome Web Store 'Ad Blocker' Caught Spying on Millions

On September 28, 2026, researchers at Bay Area Labs disclosed that Poper Blocker, a Chrome Web Store extension marketed as a pop-up and ad blocker, is in fact a data-harvesting tool that exfiltrates users' browsing history, screenshots, and AI chatbot conversations. The extension carries Google's green "Featured" badge and an "Established Publisher" designation, claims more than 2 million active users, and holds a 4.8-star rating across more than 81,000 reviews — yet it remained live on the Chrome Web Store as of the report, roughly five months after Bay Area Labs first reported it to Google in May 2026.


Details

AttributeValue
Extension namePoper Blocker (listed as "Pop up blocker for Chrome")
Extension IDbkkbcggnhapdmkeljlodobbkopceiche
DeveloperBig Star Labs
Chrome Web Store statusLive; carries "Featured" badge and "Established Publisher" status
Claimed users2,000,000+
Rating4.8 / 5 stars (81,000+ reviews)
Discovered byBay Area Labs
Reported to GoogleMay 2026
Google remediationNone confirmed as of September 28, 2026; Google did not respond to a request for comment
Exfiltration endpointapi2.poperblocker.com
Data stolenBrowsing history, screen captures, AI chatbot interactions

How It Worked

Building a Trustworthy Facade

Poper Blocker's Chrome Web Store listing describes an ad, tracker, malware, and phishing blocker built on Manifest V3 rules, and states the extension does not collect data. Yet the listing's own overview section acknowledges that every URL a user visits is checked against a remote database — meaning the extension routinely transmits browsing activity to Poper Blocker's servers by design. Google's "Featured" badge and "Established Publisher" status, both meant to signal a vetted and trustworthy developer, sat on top of that behavior and lent it legitimacy with users who would otherwise scrutinize a third-party ad blocker more closely.

Hiding the Payload from Review

According to researchers who spoke with DarkReading, Poper Blocker keeps its malicious logic out of its primary, reviewable codebase. Instead, it ships a lightweight interpreter that fetches and executes instructions from a command-and-control server at runtime — a design that lets the bulk of the exfiltration logic change after the extension has already passed Chrome Web Store review, despite Manifest V3's rules against remotely hosted and executed code. The extension also sits idle for roughly 24 hours after installation before activating its data-collection routines, a delay aimed at slipping past automated scanners and manual reviewers who typically test extensions immediately after submission. Code obfuscation and sandbox detection further complicate static and dynamic analysis.

Overreaching Permissions

An independent permissions scan of the extension (via CRXplorer) found several red flags beyond what a pop-up blocker needs to function:

  • externally_connectable includes a localhost wildcard, allowing any local application or compromised development server to message the extension directly.
  • Content scripts inject into 12 high-value domains, including Google, YouTube, Facebook, LinkedIn, and AI chat platforms, giving the extension the ability to read page content and intercept user interactions on those sites.
  • The webNavigation permission logs every site a user visits — functionality a pop-up blocker could achieve with the far narrower declarativeNetRequest API instead.
  • Incognito access is granted with a shared process, letting the extension correlate incognito and normal browsing sessions and undermining private-mode protections.

A separate traffic analysis published in February 2026 by researcher Q Continuum, covering 287 Chrome extensions collectively tied to 37.4 million installs, independently captured Poper Blocker sending obfuscated POST requests to api2.poperblocker.com/view/update. Decoded payloads included a capr request header populated with the currently visited site's URL, letting the receiving server tie granular browsing activity back to individual users.

A Repeat Offender

Poper Blocker is not an isolated case. Its developer, Big Star Labs, was first exposed by AdGuard in 2018, when researcher Andrey Meshkov identified seven mobile and browser apps from the company engaged in similar data theft across more than 11 million cumulative installs. Google removed the apps the day after that disclosure — but reinstated most of them roughly two weeks later with little to no change to their behavior. AdGuard also found that Big Star Labs itself was difficult to trace: a Delaware-registered entity with no real website or public footprint, using document images instead of searchable text and separate store accounts to obscure the connections between its products.

DarkReading identified two more Big Star Labs extensions — CrxMouse and BlockSite — that also currently hold "Featured" status on the Chrome Web Store despite being flagged as spyware alongside Poper Blocker nearly a decade ago. Together, the three extensions account for close to 6 million combined users still exposed to the same developer's data-collection practices.

Impact Assessment

Impact AreaDescription
Scale2 million-plus Poper Blocker users, plus roughly 4 million more across CrxMouse and BlockSite — the same developer's other "Featured" extensions
Data exposureFull browsing history, screen captures, and AI chatbot conversations, which can include credentials, proprietary business information, and personal data typed into AI tools
Platform trustGoogle's "Featured" and "Established Publisher" badges — intended to signal vetted, trustworthy software — were applied to an extension from a developer with a documented spyware history dating to 2018
Privacy controls bypassedShared-process incognito access lets the extension correlate private and normal browsing, defeating the purpose of incognito mode
Detection evasionA 24-hour post-install dormancy period, runtime-fetched instructions, code obfuscation, and sandbox detection delayed identification through both automated and manual review
Systemic riskA February 2026 study found 287 Chrome extensions, including Poper Blocker, collectively exfiltrating browsing data from 37.4 million users — indicating the problem extends well beyond one developer

Recommendations

For Individual Users

  • Open chrome://extensions and remove Poper Blocker, CrxMouse, and BlockSite immediately if any are installed.
  • Review recent account activity and browsing-linked services for signs of misuse, and rotate passwords or session tokens for sensitive accounts accessed while the extension was active.
  • Before installing any extension, check requested permissions rather than relying on star ratings or Chrome Web Store badges — avoid granting broad host access, webNavigation, or incognito access unless the extension's core function genuinely requires it.

For IT and Security Teams

  • Use Chrome enterprise policy (ExtensionInstallBlocklist) to block the extension ID bkkbcggnhapdmkeljlodobbkopceiche, along with the CrxMouse and BlockSite extension IDs, across managed fleets.
  • Move toward an ExtensionInstallAllowlist model for browser extensions rather than trusting Chrome Web Store "Featured" or "Established Publisher" labels as a vetting signal.
  • Add api2.poperblocker.com and related Big Star Labs infrastructure to DNS/proxy blocklists and monitor for related egress patterns.
  • Periodically audit installed extensions across the organization against known spyware and adware developer lists, not just at initial deployment.

For Platform Governance

  • Treat this as evidence that Chrome Web Store enforcement is not keeping pace with its own trust badges; a developer with an eight-year documented history of reinstated spyware should face a developer-level ban, not repeated single-extension takedowns.
  • Track the five-month gap between Bay Area Labs' May 2026 report and continued availability as a benchmark for evaluating platform response times going forward.

Key Takeaways

  1. Poper Blocker, a Chrome Web Store extension with more than 2 million users and Google's "Featured" and "Established Publisher" badges, exfiltrates browsing history, screenshots, and AI chatbot conversations, according to Bay Area Labs.
  2. The extension hides its malicious logic behind a runtime interpreter that fetches instructions from a command-and-control server, combined with a 24-hour post-install dormancy period, to evade review and detection.
  3. Bay Area Labs reported the extension to Google in May 2026; it remained live and "Featured" as of the September 28, 2026 disclosure, with no confirmed remediation from Google.
  4. Poper Blocker's developer, Big Star Labs, was first exposed running spyware across 11 million-plus installs in 2018; Google briefly removed its apps before reinstating most of them roughly two weeks later.
  5. Two more Big Star Labs extensions, CrxMouse and BlockSite, remain "Featured" on the Chrome Web Store despite the same history, adding roughly 4 million more affected users.
  6. A separate February 2026 study identified 287 Chrome extensions, including Poper Blocker, collectively exfiltrating browsing data from 37.4 million users — underscoring a Chrome Web Store vetting gap that extends well beyond this single case.

Sources