Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History, Screenshots, and AI Chatbot Conversations From Millions

Poper Blocker Chrome Extension Spyware (TL-2026-2739) is a high-severity malware campaign, first published 2026-09-28. It is attributed to Big Star Labs with high confidence, affects Big Star Labs Poper Blocker (Chrome extension, ID, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1071.001), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2739

Threat ID
TL-2026-2739
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-28
Last reviewed
2026-09-28
Attribution
Big Star Labs
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
consumer, cross-sector
Target regions
Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in Poper Blocker Chrome Extension Spyware

Malware and tooling: Big Star Labs extension spyware

The Chrome Web Store extension "Poper Blocker" (2M+ active users, 4.8-star rating, "Featured"/"Established Publisher" status) was found by Bay Area Labs to exfiltrate complete browsing history, page screenshots, scraped page content, and full Claude/ChatGPT/Gemini chatbot conversations. It idles for 24 hours post-install to evade Google reviewers and researchers, downloads and interprets obfuscated numeric commands from a command-and-control server, and discloses its data-sale practices only deep in its privacy policy. Bay Area Labs reported it to Google in May 2026; as of this report the extension remains live, and it is the third Chrome Web Store product from the same publisher, Big Star Labs, first identified as a spyware operator by AdGuard in 2018.

How Poper Blocker Chrome Extension Spyware works

Poper Blocker, listed on the Chrome Web Store as "Pop up blocker for Chrome(TM) - Poper Blocker" (extension ID bkkbcggnhapdmkeljlodobbkopceiche), presents itself as a conventional ad- and popup-blocking utility. It carries Google's green "Featured" badge and its developer holds "Established Publisher" status, a designation Google awards for verified identity and a clean policy-compliance track record. Bay Area Labs' automated testing found the extension behaves very differently from its stated purpose: on every page load it transmits the complete, unabridged URL visited (not merely pages where a popup was blocked), and it is capable of taking screenshots of the desktop and scraping arbitrary page content. Most notably for 2026, Bay Area Labs found Poper Blocker records and exfiltrates users' Claude, ChatGPT, and Gemini chatbot sessions -- prompts, responses, conversation titles, model selection, and account/subscription details -- turning a browser utility into a channel for harvesting sensitive AI-assistant conversations that may contain proprietary code, credentials, health, financial, or legal information.

To evade both the Chrome Web Store's automated/manual review and independent researchers, the extension sits idle for 24 hours after installation before activating any of its data-collection logic, a classic sandbox/analysis-window evasion. It further keeps its malicious logic outside its primary, reviewable codebase: the shipped extension bundles a lightweight interpreter that fetches and executes instructions from a remote command-and-control server at runtime, referencing commands by number rather than name and encoding/obfuscating the payloads it exchanges, which frustrates static analysis of the extension as submitted to the store. The extension's privacy policy nominally denies sharing "Personal Information" but, deeper in the document, discloses sharing with undefined "Affiliated Companies" and "third-party service providers" -- the actual data-sale relationship Bay Area Labs flagged as materially misleading.

Bay Area Labs attributes Poper Blocker to Big Star Labs, a Delaware-registered developer that Dark Reading confirmed also publishes two other Chrome Web Store extensions still live and Featured as of this report: CrxMouse (Chrome extension ID jlgkpaicikihijadgifklkbpdajbkhjo) and Block Site (Chrome extension ID eiimnmioipafcokbfikbljfdeojpcgbh), together with Poper Blocker serving roughly four million active users. This is not Big Star Labs' first exposure: AdGuard publicly identified the company in July 2018 as operating seven browser extensions and mobile/iOS apps -- an earlier generation of the same Poper Blocker, Block Site, and CrxMouse products, plus Android apps (Speed BOOSTER, Battery Saver, Clean Droid) and an iOS app (AdblockPrime) -- with more than 11 million cumulative installs. AdGuard's investigation found the Android apps abused the OS Accessibility Service (the same permission class most banking trojans rely on) to read browser address-bar URLs, and that AdblockPrime installed an MDM profile on iOS granting traffic interception and device-wide data access. Despite that 2018 public disclosure, Big Star Labs' Chrome Web Store presence was never durably remediated, and the company has since added AI-chatbot-conversation theft to its collection scope. Bay Area Labs reported its 2026 findings to Google in May 2026; Google had not removed the extension or responded to Dark Reading's request for comment as of this report, and Poper Blocker remains installable with its "Featured" and "Established Publisher" badges intact.

The pattern -- an ad-blocking or utility extension covertly harvesting AI chatbot conversations -- is not unique to Big Star Labs: in January 2026, The Hacker News and other outlets reported a separate campaign ("Smart Adblocker" and "Adblock for Browser", ~900,000 combined installs, published under different developer accounts, exfiltrating to smartadblocker[.]com and abforbrowser[.]com) using the same technique of patching global fetch/XMLHttpRequest/WebSocket calls to intercept and buffer ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok, and Meta AI conversations before exfiltration. That campaign is operationally and infrastructurally distinct from Big Star Labs/Poper Blocker (different store listings, different domains, different developer identity) but demonstrates AI-conversation theft has become a repeatable monetization technique for extensions distributed through official browser stores.

MITRE ATT&CK techniques used in TL-2026-2739

Collection

T1005 Data from Local System; T1113 Screen Capture; T1119 Automated Collection

Stealth

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1497.003 Time Based Checks; T1620 Reflective Code Loading

Command and Control

T1071.001 Web Protocols

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery

Persistence

T1176 Software Extensions

Initial Access

T1195.002 Compromise Software Supply Chain

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Domains; T1608.001 Upload Malware

Affected products and versions in Poper Blocker Chrome Extension Spyware

  • Big Star Labs — Poper Blocker (Chrome extension, ID bkkbcggnhapdmkeljlodobbkopceiche)
    Vulnerable versions: all versions live as of 2026-09
  • Big Star Labs — Poper Blocker (Edge extension, ID baplddocidbpmmneofgnhkjojmibmpck)
    Vulnerable versions: all versions live as of 2026-09
  • Big Star Labs — Poper Blocker (Firefox extension)
    Vulnerable versions: all versions live as of 2026-09
  • Big Star Labs — Poper Blocker (Android app, com.poperblocker.android)
    Vulnerable versions: all versions live as of 2026-09
  • Big Star Labs — CrxMouse (Chrome extension, ID jlgkpaicikihijadgifklkbpdajbkhjo)
    Vulnerable versions: all versions live as of 2026-09
  • Big Star Labs — Block Site (Chrome extension, ID eiimnmioipafcokbfikbljfdeojpcgbh; Firefox; Android)
    Vulnerable versions: all versions live as of 2026-09

Remediation for Poper Blocker Chrome Extension Spyware

Patches

  • No vendor patch exists; as of this report Google has not removed Poper Blocker, CrxMouse, or Block Site from the Chrome Web Store despite the May 2026 disclosure

Immediate actions

  • Uninstall Poper Blocker, CrxMouse, and Block Site (all platforms) from managed and BYOD browsers via MDM/enterprise browser management
  • Block outbound traffic to api2.poperblocker.com, api.taskapi.net, yourblocksite.com, and ben.crxmouse.com at DNS/perimeter
  • Treat any Claude, ChatGPT, or Gemini conversations conducted on an affected browser as potentially exposed; rotate credentials, API keys, or secrets pasted into those sessions
  • Audit Chrome/Edge/Firefox extension inventories for extension IDs bkkbcggnhapdmkeljlodobbkopceiche, baplddocidbpmmneofgnhkjojmibmpck, jlgkpaicikihijadgifklkbpdajbkhjo, and eiimnmioipafcokbfikbljfdeojpcgbh

Workarounds

  • Replace with a vetted, open-source ad-blocking extension (e.g., uBlock Origin) restricted to an enterprise extension allowlist

Longer-term hardening

  • Enforce an enterprise browser-extension allowlist rather than trusting Chrome Web Store "Featured"/"Established Publisher" badges as a safety signal
  • Deploy extension risk-scoring/DLP tooling that flags broad host-permission extensions egressing to non-vendor domains or fetching remotely-interpreted code
  • Establish periodic re-review of previously-flagged extension publishers -- Big Star Labs' spyware was publicly documented in 2018 and persisted unremediated for eight years

Weaknesses (CWE) in Poper Blocker Chrome Extension Spyware

CWE-200, CWE-359

Timeline of Poper Blocker Chrome Extension Spyware

  • AdGuard publishes the first public report identifying Big Star Labs as operating seven spyware-laced browser extensions and mobile/iOS apps -- including earlier versions of Poper Blocker, CrxMouse, and Block Site -- with more than 11 million cumulative installs, citing Accessibility Service abuse on Android and MDM-profile abuse on iOS.
  • In January 2026, The Hacker News reports a separate, unrelated campaign ("Smart Adblocker" and "Adblock for Browser") stealing ChatGPT and DeepSeek conversations from roughly 900,000 users, establishing AI-chatbot-conversation theft as a repeatable ad-blocker-disguised spyware technique ahead of the Poper Blocker findings.
  • Bay Area Labs reports its Poper Blocker findings -- full browsing-history collection, screenshot/page-scrape capability, and Claude/ChatGPT/Gemini conversation exfiltration -- directly to Google (reported in May 2026).
  • Dark Reading identifies two additional Big Star Labs extensions, CrxMouse and Block Site, still live and "Featured" on the Chrome Web Store, bringing the publisher's active install base across at least three extensions to roughly four million users.
  • Dark Reading publishes Bay Area Labs' findings in detail, describing Poper Blocker's 24-hour post-install dormancy period, its C2-driven interpreter with obfuscated numeric commands, and its Claude/ChatGPT/Gemini conversation theft.
  • As of this report, Google has taken no visible action on the May 2026 disclosure: Poper Blocker remains live on the Chrome Web Store carrying its "Featured" badge and the developer's "Established Publisher" status.

Sources cited for Poper Blocker Chrome Extension Spyware

More in malware

Detection coverage for TL-2026-2739

As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2739 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats