Chrome Web Store Extension “Poper Blocker” Distributes Spyware to Millions of Users
What Happened — A Chrome Web Store extension marketed as an ad‑blocker, Poper Blocker, was found to contain hidden code that harvests browsing history, cookies, and login credentials before sending the data to remote servers. Independent researchers reported that the extension has been downloaded millions of times despite warnings from security analysts.
Why It Matters for Trust & Control Assurance
- The incident exemplifies a supply‑chain risk where a trusted third‑party marketplace delivers malicious software to end users, a scenario continuous control‑assurance programs are built to detect and document.
- Demonstrates the need for ongoing vendor‑risk monitoring and evidence collection on all third‑party components (extensions, SDKs, APIs) that interact with corporate assets.
- Highlights the importance of maintaining a defensible audit trail that shows due‑diligence in vetting and revoking unauthorized software.
Who Is Affected — Any organization whose workforce uses Google Chrome on corporate devices, spanning finance, healthcare, technology, and public‑sector environments.
Recommended Actions
- Immediately remove Poper Blocker from all managed browsers.
- Deploy an extension‑allowlist policy and enforce it through endpoint management tools.
- Conduct an inventory of installed browser extensions across the enterprise and capture evidence for audit readiness.
- Integrate continuous third‑party risk monitoring to flag newly published extensions that request excessive permissions.
Technical Notes
- The extension requests “read and change all your data on the websites you visit” and “access browser tabs”.
- Exfiltration occurs via HTTPS POST to a command‑and‑control domain observed in multiple samples.
- No CVE is associated; the threat vector is a malicious third‑party dependency hosted on a reputable marketplace.
Source: Dark Reading