Researchers allege that Poper Blocker, a Chrome popup and ad-blocking extension with more than 2 million users, covertly collects complete browsing URLs and referrers, AI-chat content, advertising and social-media data, and browser-fingerprint information. The extension reportedly contains an obfuscated interpreter that retrieves remotely hosted programs and a command dictionary from api.pbapi.xyz, allowing its operator to change collection and exfiltration behavior without submitting a new Chrome Web Store-reviewed update. Researchers also reported that the same remote capability can inspect page content, HTTP request and response bodies, and WebSocket traffic; capture page-region screenshots; compress collected data; and upload it to destinations selected by the server.
The report describes delayed payload delivery, sandbox and automation detection, consent gates, code obfuscation, and use of a cross-device identifier drawn from Chrome Sync storage as anti-analysis and tracking measures. Poper Blocker reportedly remained featured and verified in the Chrome Web Store after an earlier May report alleged AI-chat scraping, while its Microsoft Edge listing is said to use the same remote configuration. If confirmed, the reported data collection and remotely alterable behavior would conflict with Chrome Web Store Limited Use requirements, which limit Google API-derived user data to disclosed, single user-facing purposes and prohibit undisclosed transfers, advertising use, and other restricted processing.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Google's Chrome Web Store Limited Use policy set minimum privacy requirements for extension user data, restricting use, transfer, sale, advertising use, and human access to such data.
A technical report alleged that the Poper Blocker extension collects full browsing URLs, AI-chat content, advertising and social-media data, and browser-fingerprint information. It described a remotely controlled interpreter and payload system that can alter collection and upload behavior without a Chrome Web Store extension update.
Researchers reported that Google was publicly notified about allegations that Poper Blocker scraped AI-chat data. The report states that the extension remained available in the Chrome Web Store afterward.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.