Chrome Web Store 'Poper Blocker' Extension Exfiltrates User Data
Malicious extension bypasses Google's review process, affects millions of users

Key Takeaways
- The 'Poper Blocker' extension was available on the Google Chrome Web Store and amassed millions of downloads.
- The extension functioned as spyware, exfiltrating browsing data, cookies, and session information.
- Researchers warned of the extension's malicious nature prior to its removal.
- Google removed the extension from the Chrome Web Store following the disclosure.
- The incident underscores the need for improved vetting mechanisms for browser extensions.
Quick answers
- What happened?
- A browser extension named 'Poper Blocker' available on the Google Chrome Web Store has been identified as spyware that exfiltrates sensitive user data. Despite reports from researchers warning of its malicious nature, the extension maintained Google's seal of approval and was downloaded by millions of users before being removed.
- Which products are affected?
- Google Chrome
- What should defenders do?
- Users are advised to review and remove any suspicious browser extensions. Google has removed 'Poper Blocker' from the Chrome Web Store. It is recommended to keep browsers and extensions updated and to only install extensions from trusted developers with high user counts and recent updates.
According to cybersecurity researchers, the 'Poper Blocker' extension, which purports to block pop-up advertisements, was found to be engaging in covert data collection. The extension harvested browsing history, cookies, and other session data, transmitting it to remote servers controlled by the threat actor. The malicious activity was discovered after users reported unusual browser behavior and elevated network traffic. While Google has since removed the extension from the Chrome Web Store, the incident highlights ongoing challenges in the vetting process for browser extensions and the potential for malicious actors to abuse trusted platforms. The extension's presence on the store for an extended period suggests it may have bypassed initial security reviews or updated its behavior after passing initial checks.
Security Details
The 'Poper Blocker' extension was found to exfiltrate sensitive user data, including browsing history and cookies, to remote servers.
Affected products
Google Chrome
Mitigation
Users are advised to review and remove any suspicious browser extensions. Google has removed 'Poper Blocker' from the Chrome Web Store. It is recommended to keep browsers and extensions updated and to only install extensions from trusted developers with high user counts and recent updates.
Sources
Dark reading
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
Sep 28, 2026 · 16:51
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




