Based on information from Dark Reading, millions of users have unknowingly downloaded infostealer malware disguised as legitimate ad-blocking browser extensions, with Google's Chrome Web Store inadvertently providing a platform for these malicious applications.Researchers at Bay Area Labs have identified "Poper Blocker," an ad-blocking extension with a "Featured" badge and "Established Publisher" status from Google, as malware. Despite its high ratings and over two million users, Poper Blocker exfiltrates sensitive data including browser histories, screenshots, and AI chatbot interactions. It employs techniques like code obfuscation and sandbox detection to evade security measures.This is not an isolated incident; two other popular extensions from the same developer, identified as spyware nearly a decade ago, also hold "featured" status on the Chrome Web Store. Google was notified in May 2026, but the extensions remain available. The developer, Big Star Labs, has a history of distributing spyware, with multiple apps previously removed by Google only to be reinstated. Cybersecurity tools may struggle to detect such threats due to advanced obfuscation techniques used by the malware.Source: Dark Reading
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
