Malware

Malicious ad-blocking extensions exploit Chrome Web Store trust

Based on information from Dark Reading, millions of users have unknowingly downloaded infostealer malware disguised as legitimate ad-blocking browser extensions, with Google's Chrome Web Store inadvertently providing a platform for these malicious applications.

Researchers at Bay Area Labs have identified "Poper Blocker," an ad-blocking extension with a "Featured" badge and "Established Publisher" status from Google, as malware. Despite its high ratings and over two million users, Poper Blocker exfiltrates sensitive data including browser histories, screenshots, and AI chatbot interactions. It employs techniques like code obfuscation and sandbox detection to evade security measures.

This is not an isolated incident; two other popular extensions from the same developer, identified as spyware nearly a decade ago, also hold "featured" status on the Chrome Web Store. Google was notified in May 2026, but the extensions remain available. The developer, Big Star Labs, has a history of distributing spyware, with multiple apps previously removed by Google only to be reinstated. Cybersecurity tools may struggle to detect such threats due to advanced obfuscation techniques used by the malware.

Source: Dark Reading

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds