Popular Chrome Ad Blocker Accused of Secretly Harvesting Browsing and AI Chat Data
Poper Blocker, a Chrome extension with 2M users, accused of harvesting browsing history, AI chats, and screenshots via remote commands.
Illustrative image generated with AI
A trusted-looking extension with more than 2 million users
Poper Blocker, a widely installed ad-blocking extension, has been accused of collecting browsing histories, page contents, screenshots, location estimates, and conversations with major AI chatbots.
Bay Area Labs says the extension sends the captured information to remote infrastructure while using several techniques to avoid automated review and security analysis. The findings were reported on September 28, 2026.
The scale is significant. Poper Blocker claims more than 2 million active users through the Google Chrome Web Store, where it has a 4.8 out of 5 rating from over 81,000 reviewers. It also carries Google’s Featured and Established Publisher badges.
Those trust signals could lead users to assume that both the extension and its publisher have undergone meaningful scrutiny. The Established Publisher designation indicates that Google has established the publisher’s identity and reviewed its history of policy compliance.
Bay Area Labs reported Poper Blocker to Google in May 2026. According to the published investigation into the extension, it remained available at publication time. Google and developer Big Star Labs had not responded publicly to requests for comment.
No affected version range has been disclosed. The report also provides no CVE identifier, CVSS score, formal severity rating, patch, or confirmed technical remediation.
Collection reaches inside web pages and AI conversations
The alleged surveillance goes well beyond the telemetry commonly associated with browser extensions.
Poper Blocker reportedly records the complete URL of every page visited. It can also capture screenshots and scrape information directly from pages, potentially exposing content that does not appear in an address bar.
The collection reportedly includes conversations conducted through Claude, ChatGPT, and Gemini. Captured records may contain:
- User prompts and model responses
- Conversation titles
- The AI model selected
- Subscription-tier information
- Records presented as models’ thought processes
This creates risks for both individuals and organizations. AI conversations can contain proprietary code, internal documents, customer records, legal questions, incident-response details, medical information, or credentials pasted into a prompt.
Page scraping and screenshot capabilities broaden the exposure further. Information displayed inside corporate dashboards, webmail, cloud administration consoles, financial services, or internal applications could potentially be collected even when the visited URL reveals little by itself.
Bay Area Labs also says the extension estimates users’ locations and assigns cross-device identifiers. Such identifiers can associate browsing activity from different devices with the same person, producing a more complete behavioral profile.
The extension’s store listing briefly acknowledges receiving and analyzing information about visited websites. Its privacy policy reportedly describes wider collection and says user data may be sold to third parties. It also recognizes that browsing information can include sensitive data and that affiliates may disclose it to customers for market research or consumer-behavior analysis.
Remote commands keep the sensitive logic outside the extension
The most consequential technical finding concerns how Poper Blocker allegedly obtains its instructions.
Instead of placing all relevant functionality directly in the extension package, it reportedly contains an interpreter that downloads commands from an attacker-controlled command-and-control service. The interpreter then executes those remotely supplied instructions.
That architecture makes static inspection less effective. A reviewer examining the package may see the interpreter but not the complete sequence of operations that it will later receive.
The extension reportedly waits 24 hours after installation before downloading the components associated with the malicious activity. This delay can help it outlast short automated tests, review sessions, or sandbox runs.
Researchers identified several additional evasion mechanisms:
- Payloads are encoded and obfuscated.
- Operations use numeric identifiers rather than descriptive command names.
- The dictionary needed to interpret those identifiers comes from the remote C2 service.
- The extension checks whether it is executing inside a sandbox.
- Its C2 domain can be changed remotely.
The remote-interpreter model reportedly conflicts with Google’s Manifest V3 rules. MV3 places restrictions on remotely hosted code so that an extension’s behavior can be assessed from the software submitted to the store. Fetching instructions that determine sensitive runtime behavior can defeat that review objective.
Obfuscation also complicates enterprise monitoring. Data-loss-prevention tools often search outbound traffic for known formats, recognizable field names, or regular-expression matches. Encoded or transformed records may not trigger those rules, particularly when the extension is communicating through ordinary browser processes.
James Arnott, founder of Bay Area Labs, said identifying the transmissions may require manual analysis by someone capable of reconstructing the obfuscated data and its outbound path.
The opt-out mechanism may not provide reliable protection
Users can reportedly refuse third-party data sharing, but the available control raises additional concerns.
According to the researchers, users who decline are shown a prompt on every page warning that advanced ad-blocking functions will not work unless they agree. Repetition can pressure users into changing their selection simply to stop the interruptions.
The interface is also described as deceptive. The toggle turns green when the user opts in, creating a visual design that favors consent rather than presenting both choices neutrally.
More importantly, there is no confirmation that opting out stops all alleged collection or exfiltration. The control is described in relation to third-party data sharing, not necessarily the extension’s acquisition of browsing records, screenshots, page contents, identifiers, or AI conversations.
Users should therefore not treat the opt-out as a verified technical safeguard.
Big Star Labs has been linked to earlier spyware findings
Poper Blocker is associated with Big Star Labs, which also publishes CrxMouse and BlockSite. The three Chrome extensions together have nearly 4 million users. BlockSite has additionally accumulated more than 10 million downloads through Google Play.
The current technical findings principally concern Poper Blocker. No affected versions have been identified, and the available information does not establish that CrxMouse or BlockSite currently perform the same operations.
However, the publisher has faced similar allegations before. In 2018, AdGuard identified seven mobile and browser applications developed by Big Star Labs as conducting malicious data theft. Those products had more than 11 million users combined.
Google removed Big Star Labs applications from the Chrome Web Store following that disclosure. Some were restored two weeks later. Poper Blocker, CrxMouse, and BlockSite currently remain listed and carry the Established Publisher badge.
Questions also surround the developer’s corporate identity. LinkedIn information describes Big Star Labs as founded in 2010 at a central London WeWork location. Its page lists three employees whose profile photographs are free stock images.
In 2017, the company registered as a limited partnership in Delaware, where public filings do not require the identification of owners and operators. Its registered address was an unmarked building shared with several other shell companies.
Users and administrators should prioritize removal and investigation
There is no vendor patch or confirmed workaround. Given the reported ability to receive remote commands, simply changing an extension setting cannot establish what code will execute later.
For users who do not accept that risk, removing Poper Blocker is the clearest immediate measure. Chrome users should also review their installed extensions and eliminate unnecessary ad blockers or other tools with broad access to website data.
Organizations can take additional steps:
- Block or remove Poper Blocker through browser-management policies.
- Inventory CrxMouse and BlockSite separately, while avoiding assumptions that the same behavior has been confirmed in those products.
- Review proxy, DNS, and endpoint telemetry for unusual outbound traffic generated through Chrome, recognizing that the C2 domain can change.
- Investigate sensitive information entered into AI services from browsers where Poper Blocker was installed.
- Rotate credentials or secrets exposed in chatbot prompts or web pages when there is a credible possibility they were captured.
- Preserve the extension and relevant browser logs if forensic investigation is required.
- Do not rely solely on DLP signatures, because encoding and obfuscation may conceal the transmitted content.
Bay Area Labs’ automated testing found that one in five ad blockers with more than 100,000 users exfiltrated browser histories in some form. Some results had not yet been manually confirmed, so the other suspected extensions were not publicly named.
That finding does not establish that every popular ad blocker is unsafe. It does show that store ratings, installation counts, and publisher badges cannot substitute for restrictive permissions, extension inventories, traffic analysis, and careful review of data-collection policies.
Sources
This article is an original reworking based on the sources below.




