Chrome Store Hosts ‘Poper Blocker’ Spyware Downloaded by Millions

Millions of Chrome Users Infected with Malicious Ad-Blocker Extension

A staggering number of people have downloaded a spyware-laced ad-blocker extension from the Chrome Web Store, thanks in part to its impressive credentials and seal of approval from Google. Poper Blocker, as it’s called, has been masquerading as a legitimate tool, boasting an impressive 4.8-star rating and over 2 million active users. However, researchers at Bay Area Labs have uncovered its true nature – a malicious program designed to exfiltrate sensitive data from unsuspecting users.

Poper Blocker operates by recording extensive browsing histories, including detailed URLs, screengrabs, and even AI chatbot interactions. It achieves this through classic malware techniques such as code obfuscation and sandbox detection, making it difficult for cybersecurity researchers to detect its malicious activity. The extension also assigns cross-device IDs to users, allowing it to associate data collected across multiple devices with the same individual.

What’s particularly concerning is that Poper Blocker isn’t an isolated incident. Bay Area Labs has identified two other popular apps from the same developer that have been masquerading as legitimate extensions on the Chrome Web Store for nearly a decade. Despite warnings from researchers, these apps remain available to download, further highlighting the need for improved security measures within the Chrome ecosystem.

Google’s role in this debacle is also under scrutiny. In May 2026, Bay Area Labs reported Poper Blocker to Google, but it appears that no action was taken. When approached by Dark Reading for comment, Google failed to respond. This lack of accountability raises questions about how such malicious apps can persist on the Chrome Web Store.

The data collection practices employed by Poper Blocker are also disturbingly transparent. The app acknowledges collecting browsing data and selling it to third parties in its Privacy Policy, which is buried deep within its documentation. Users who opt out of data sharing receive a popup warning that “advanced [ad] blocking features won’t activate” until they comply – an obvious attempt to coerce users into submitting their sensitive information.

To make matters worse, Poper Blocker employs a command-and-control (C2) server to download and interpret instructions from its developers. This allows the malicious extension to remain hidden from Google reviewers and cybersecurity researchers, who often rely on signature-based detection methods that struggle to keep pace with evolving malware tactics.

In light of this incident, users are advised to exercise extreme caution when downloading extensions from the Chrome Web Store. Be wary of apps that promise impressive features or high ratings without providing clear explanations of their data collection practices. Remember that even legitimate-looking extensions can harbor malicious functionality, and always opt for transparency over convenience. By being more vigilant in our digital interactions, we can help prevent such incidents from occurring in the future.


Source: Dark Reading — 2026-09-28