Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History, Screenshots, and AI Chatbot Conversations From Millions
Poper Blocker Chrome Extension Spyware (TL-2026-2739) is a high-severity malware campaign, first published 2026-09-28. It is attributed to Big Star Labs with high confidence, affects Big Star Labs Poper Blocker (Chrome extension, ID, maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1071.001), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2739
- Threat ID
- TL-2026-2739
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution
- Big Star Labs
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- consumer, cross-sector
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Poper Blocker Chrome Extension Spyware
Malware and tooling: Big Star Labs extension spyware
The Chrome Web Store extension "Poper Blocker" (2M+ active users, 4.8-star rating, "Featured"/"Established Publisher" status) was found by Bay Area Labs to exfiltrate complete browsing history, page screenshots, scraped page content, and full Claude/ChatGPT/Gemini chatbot conversations. It idles for 24 hours post-install to evade Google reviewers and researchers, downloads and interprets obfuscated numeric commands from a command-and-control server, and discloses its data-sale practices only deep in its privacy policy. Bay Area Labs reported it to Google in May 2026; as of this report the extension remains live, and it is the third Chrome Web Store product from the same publisher, Big Star Labs, first identified as a spyware operator by AdGuard in 2018.
How Poper Blocker Chrome Extension Spyware works
Poper Blocker, listed on the Chrome Web Store as "Pop up blocker for Chrome(TM) - Poper Blocker" (extension ID bkkbcggnhapdmkeljlodobbkopceiche), presents itself as a conventional ad- and popup-blocking utility. It carries Google's green "Featured" badge and its developer holds "Established Publisher" status, a designation Google awards for verified identity and a clean policy-compliance track record. Bay Area Labs' automated testing found the extension behaves very differently from its stated purpose: on every page load it transmits the complete, unabridged URL visited (not merely pages where a popup was blocked), and it is capable of taking screenshots of the desktop and scraping arbitrary page content. Most notably for 2026, Bay Area Labs found Poper Blocker records and exfiltrates users' Claude, ChatGPT, and Gemini chatbot sessions -- prompts, responses, conversation titles, model selection, and account/subscription details -- turning a browser utility into a channel for harvesting sensitive AI-assistant conversations that may contain proprietary code, credentials, health, financial, or legal information.
To evade both the Chrome Web Store's automated/manual review and independent researchers, the extension sits idle for 24 hours after installation before activating any of its data-collection logic, a classic sandbox/analysis-window evasion. It further keeps its malicious logic outside its primary, reviewable codebase: the shipped extension bundles a lightweight interpreter that fetches and executes instructions from a remote command-and-control server at runtime, referencing commands by number rather than name and encoding/obfuscating the payloads it exchanges, which frustrates static analysis of the extension as submitted to the store. The extension's privacy policy nominally denies sharing "Personal Information" but, deeper in the document, discloses sharing with undefined "Affiliated Companies" and "third-party service providers" -- the actual data-sale relationship Bay Area Labs flagged as materially misleading.
Bay Area Labs attributes Poper Blocker to Big Star Labs, a Delaware-registered developer that Dark Reading confirmed also publishes two other Chrome Web Store extensions still live and Featured as of this report: CrxMouse (Chrome extension ID jlgkpaicikihijadgifklkbpdajbkhjo) and Block Site (Chrome extension ID eiimnmioipafcokbfikbljfdeojpcgbh), together with Poper Blocker serving roughly four million active users. This is not Big Star Labs' first exposure: AdGuard publicly identified the company in July 2018 as operating seven browser extensions and mobile/iOS apps -- an earlier generation of the same Poper Blocker, Block Site, and CrxMouse products, plus Android apps (Speed BOOSTER, Battery Saver, Clean Droid) and an iOS app (AdblockPrime) -- with more than 11 million cumulative installs. AdGuard's investigation found the Android apps abused the OS Accessibility Service (the same permission class most banking trojans rely on) to read browser address-bar URLs, and that AdblockPrime installed an MDM profile on iOS granting traffic interception and device-wide data access. Despite that 2018 public disclosure, Big Star Labs' Chrome Web Store presence was never durably remediated, and the company has since added AI-chatbot-conversation theft to its collection scope. Bay Area Labs reported its 2026 findings to Google in May 2026; Google had not removed the extension or responded to Dark Reading's request for comment as of this report, and Poper Blocker remains installable with its "Featured" and "Established Publisher" badges intact.
The pattern -- an ad-blocking or utility extension covertly harvesting AI chatbot conversations -- is not unique to Big Star Labs: in January 2026, The Hacker News and other outlets reported a separate campaign ("Smart Adblocker" and "Adblock for Browser", ~900,000 combined installs, published under different developer accounts, exfiltrating to smartadblocker[.]com and abforbrowser[.]com) using the same technique of patching global fetch/XMLHttpRequest/WebSocket calls to intercept and buffer ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok, and Meta AI conversations before exfiltration. That campaign is operationally and infrastructurally distinct from Big Star Labs/Poper Blocker (different store listings, different domains, different developer identity) but demonstrates AI-conversation theft has become a repeatable monetization technique for extensions distributed through official browser stores.
MITRE ATT&CK techniques used in TL-2026-2739
Collection
T1005 Data from Local System; T1113 Screen Capture; T1119 Automated Collection
Stealth
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1497.003 Time Based Checks; T1620 Reflective Code Loading
Command and Control
Discovery
T1082 System Information Discovery; T1217 Browser Information Discovery
Persistence
Initial Access
T1195.002 Compromise Software Supply Chain
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in Poper Blocker Chrome Extension Spyware
- Big Star Labs — Poper Blocker (Chrome extension, ID bkkbcggnhapdmkeljlodobbkopceiche)
Vulnerable versions: all versions live as of 2026-09 - Big Star Labs — Poper Blocker (Edge extension, ID baplddocidbpmmneofgnhkjojmibmpck)
Vulnerable versions: all versions live as of 2026-09 - Big Star Labs — Poper Blocker (Firefox extension)
Vulnerable versions: all versions live as of 2026-09 - Big Star Labs — Poper Blocker (Android app, com.poperblocker.android)
Vulnerable versions: all versions live as of 2026-09 - Big Star Labs — CrxMouse (Chrome extension, ID jlgkpaicikihijadgifklkbpdajbkhjo)
Vulnerable versions: all versions live as of 2026-09 - Big Star Labs — Block Site (Chrome extension, ID eiimnmioipafcokbfikbljfdeojpcgbh; Firefox; Android)
Vulnerable versions: all versions live as of 2026-09
Remediation for Poper Blocker Chrome Extension Spyware
Patches
- No vendor patch exists; as of this report Google has not removed Poper Blocker, CrxMouse, or Block Site from the Chrome Web Store despite the May 2026 disclosure
Immediate actions
- Uninstall Poper Blocker, CrxMouse, and Block Site (all platforms) from managed and BYOD browsers via MDM/enterprise browser management
- Block outbound traffic to api2.poperblocker.com, api.taskapi.net, yourblocksite.com, and ben.crxmouse.com at DNS/perimeter
- Treat any Claude, ChatGPT, or Gemini conversations conducted on an affected browser as potentially exposed; rotate credentials, API keys, or secrets pasted into those sessions
- Audit Chrome/Edge/Firefox extension inventories for extension IDs bkkbcggnhapdmkeljlodobbkopceiche, baplddocidbpmmneofgnhkjojmibmpck, jlgkpaicikihijadgifklkbpdajbkhjo, and eiimnmioipafcokbfikbljfdeojpcgbh
Workarounds
- Replace with a vetted, open-source ad-blocking extension (e.g., uBlock Origin) restricted to an enterprise extension allowlist
Longer-term hardening
- Enforce an enterprise browser-extension allowlist rather than trusting Chrome Web Store "Featured"/"Established Publisher" badges as a safety signal
- Deploy extension risk-scoring/DLP tooling that flags broad host-permission extensions egressing to non-vendor domains or fetching remotely-interpreted code
- Establish periodic re-review of previously-flagged extension publishers -- Big Star Labs' spyware was publicly documented in 2018 and persisted unremediated for eight years
Weaknesses (CWE) in Poper Blocker Chrome Extension Spyware
CWE-200, CWE-359
Timeline of Poper Blocker Chrome Extension Spyware
- AdGuard publishes the first public report identifying Big Star Labs as operating seven spyware-laced browser extensions and mobile/iOS apps -- including earlier versions of Poper Blocker, CrxMouse, and Block Site -- with more than 11 million cumulative installs, citing Accessibility Service abuse on Android and MDM-profile abuse on iOS.
- In January 2026, The Hacker News reports a separate, unrelated campaign ("Smart Adblocker" and "Adblock for Browser") stealing ChatGPT and DeepSeek conversations from roughly 900,000 users, establishing AI-chatbot-conversation theft as a repeatable ad-blocker-disguised spyware technique ahead of the Poper Blocker findings.
- Bay Area Labs reports its Poper Blocker findings -- full browsing-history collection, screenshot/page-scrape capability, and Claude/ChatGPT/Gemini conversation exfiltration -- directly to Google (reported in May 2026).
- Dark Reading identifies two additional Big Star Labs extensions, CrxMouse and Block Site, still live and "Featured" on the Chrome Web Store, bringing the publisher's active install base across at least three extensions to roughly four million users.
- Dark Reading publishes Bay Area Labs' findings in detail, describing Poper Blocker's 24-hour post-install dormancy period, its C2-driven interpreter with obfuscated numeric commands, and its Claude/ChatGPT/Gemini conversation theft.
- As of this report, Google has taken no visible action on the May 2026 disclosure: Poper Blocker remains live on the Chrome Web Store carrying its "Featured" badge and the developer's "Established Publisher" status.
Sources cited for Poper Blocker Chrome Extension Spyware
- Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
- "Big Star Labs" spyware campaign affects over 11,000,000 people
- Chrome Extensions, Android and iOS Apps Caught Collecting Browsing Data
- Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users
- PromptSnatcher Ad Blocker Extensions Steal AI Chats From ChatGPT, Claude, and Gemini
- Pop up blocker for Chrome(TM) - Poper Blocker
- Poper Blocker: Popup & Ad Blocker for Chrome (chrome-stats analysis)
More in malware
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
Detection coverage for TL-2026-2739
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2739 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.