Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Chrome Web Store Extension “Poper Blocker” Distributes Spyware to Millions of Users

A Chrome Web Store ad‑blocker called Poper Blocker was discovered to harvest browsing data and credentials, affecting millions of users. The episode underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of software vetting.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
darkreading.com

Chrome Web Store Extension “Poper Blocker” Distributes Spyware to Millions of Users

What Happened — A Chrome Web Store extension marketed as an ad‑blocker, Poper Blocker, was found to contain hidden code that harvests browsing history, cookies, and login credentials before sending the data to remote servers. Independent researchers reported that the extension has been downloaded millions of times despite warnings from security analysts.

Why It Matters for Trust & Control Assurance

  • The incident exemplifies a supply‑chain risk where a trusted third‑party marketplace delivers malicious software to end users, a scenario continuous control‑assurance programs are built to detect and document.
  • Demonstrates the need for ongoing vendor‑risk monitoring and evidence collection on all third‑party components (extensions, SDKs, APIs) that interact with corporate assets.
  • Highlights the importance of maintaining a defensible audit trail that shows due‑diligence in vetting and revoking unauthorized software.

Who Is Affected — Any organization whose workforce uses Google Chrome on corporate devices, spanning finance, healthcare, technology, and public‑sector environments.

Recommended Actions

  • Immediately remove Poper Blocker from all managed browsers.
  • Deploy an extension‑allowlist policy and enforce it through endpoint management tools.
  • Conduct an inventory of installed browser extensions across the enterprise and capture evidence for audit readiness.
  • Integrate continuous third‑party risk monitoring to flag newly published extensions that request excessive permissions.

Technical Notes

  • The extension requests “read and change all your data on the websites you visit” and “access browser tabs”.
  • Exfiltration occurs via HTTPS POST to a command‑and‑control domain observed in multiple samples.
  • No CVE is associated; the threat vector is a malicious third‑party dependency hosted on a reputable marketplace.

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →