Poper Blocker, an Adblocker With 2 Million Users, Sent AI Chats and Browsing History to Its Own Server

Ethical Hacking Complete Course Zero to Expert
Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.
→ Take the full courseAn adblocker with 2 million users sent ChatGPT, Claude and Gemini chats to its own server, plus their browsing history. It promised a more private web. Google was warned in May and kept it Featured.
The extension is called Poper Blocker. In the Chrome Web Store it has 4.8 stars from more than 81,000 ratings and the Featured badge. On 28 September 2026, James Arnott of Bay Area Labs, the team behind the extension scanner Am I Being Pwned, published what it does once it is in your browser.
The extension downloads small programs from its server, and 23 of the 40 it runs go after ChatGPT, Claude, Gemini and Google’s AI Mode. They take the prompts you type and the full answers you get back, with the code blocks in them and the “thinking” steps the models show.
They also take deep research reports with their sources, voice conversations, the titles of your chats, which model you use and which plan you pay for. On a work laptop that means source code and internal documents pasted in for a summary.
Next to that it collects the full address of each page you open and the page that sent you there. That includes the query string, the part of the address after the question mark.
Each upload also carries an ID taken from Chrome’s sync storage. That ID is the same on each device where you are signed in to Chrome with sync on. So the chats, the addresses and the rest of the data all lead back to one person.
To get all that, it asks you again and again until you accept. Install it, say no to data sharing, and a pop-up shows up on each page you open. It says sharing is “required” for the “advanced blocking features”, and the pop-up only goes away when you accept. In the settings sits a switch labelled as an opt out. When that switch is on, you are opted in.
The extension uploads nothing until you say yes, and out of the box it is set to no. According to the researchers, that lets the company say “the user consented”.
Normally the code of an extension is inside the package you install. The store can review it and researchers can read it. Poper Blocker ships an interpreter instead: a small piece of code that reads instructions written in the company’s own scripting language, with variables, loops and functions, and carries them out. The instructions themselves come from the company’s server, after you install it.
At startup the extension sends a request to https://api.pbapi.xyz/v2/rec and gets back a batch of programs. When the researchers asked, they got 40. A second request to /v2/config returns a numbered list of commands.
Inside the extension those commands only exist as numbers, so reading the code does not tell you what it does. The researchers searched it for the command names "aggregate", "take-image" and "upload-blob" and got zero hits for each. The programs also arrive scrambled. They are written in rows that have to be read down the columns and then base64-decoded. What goes back out is scrambled with ROT47, a fixed shift of each character.
This is the program that takes Claude conversations, trimmed down by the researchers:
| |
While you are on a claude.ai chat page, it waits for the reply from the chat API, takes the full message body and stores it under "data". That message body is your conversation.
The full list of commands goes further. With it, the server can read anything on a page, and read what the page sends to its server and what comes back, WebSocket traffic included. It can take a screenshot of any part of a page, zip the result and upload it to an address the server picks.
The 40 programs that were live on the day the researchers looked did not use the file-upload and full-page capture commands. The server can send new programs at any moment, without an update and without a new review. It can also change the address the data goes to on any response.
According to the researchers, security software at work will not catch this traffic either. A company can watch for its own data leaving the network with DLP software, or with a proxy that opens encrypted traffic. Both only see the browser send a scrambled blob to a domain that looks like nothing special. They have no keyword to match and no file to fingerprint, and the destination can change on the next response.
When the researchers installed Poper Blocker, the server sent back nothing interesting. The programs that collect your data only arrived about 24 hours later. They found that delay on the server side, so the server decides when you get them. According to the researchers, a review in a test environment runs for minutes, not days.
One of the programs, anf_t, runs on each site you visit and reports whether a test tool is driving the browser. It checks navigator.webdriver, a flag that is set when a script controls the browser. It looks for traces left by ChromeDriver and Playwright, two tools that let a script drive a browser.
And it counts the plugins, because older headless browsers, the kind that run without a screen, have none. A server that knows it is talking to a test machine can send it a clean set of programs.
The server can also hand a different set of programs to a particular timezone, language setting or group of installs, so it could be aimed at one organisation. The researchers tested this on one day with one ID, so they have not seen two different sets side by side.
Even removing the extension sends something out. While you browse, it keeps a list of the last five sites you visited and writes it into its uninstall address. The moment you remove Poper Blocker, Chrome sends a request to poperblocker.com/uninstall/ with those five domains in the lD parameter.
Poper Blocker’s homepage promises “No tracking”. The extension belongs to Big Star Labs LP, a limited partnership registered in Delaware. Its privacy policy, last changed on 5 August 2026, says it collects “the AI requests you make and the AI responses you receive”, “including any and all attachments, uploads and images”.
The company’s affiliates may pass those chats on to their customers “for market research purposes, AI model training or development”. In the section for several US states the policy says: “We sell such categories of Personal Data to our affiliates who then may sell it to their business customers.” It also names what can be in that data: religious or philosophical beliefs, health data, and information about a person’s sex life or sexual orientation.
The listing in Microsoft’s Edge store, from the same company, tells visitors the data is “Not sold to third parties outside approved use cases” and “Not used or shared for purposes unrelated to the extension’s functionality.”
On 11 May 2026, Poper Blocker went on a public list of extensions caught taking AI chats, marked as confirmed. The researcher had watched chat content leave the browser in the network traffic. It was reported to Google that same month.
Manifest V3 is the current set of rules for Chrome extensions. Its requirements forbid “Building an interpreter to run complex commands fetched from a remote source, even if those commands are fetched as data.” Four months after the warning, Poper Blocker was still Featured and still taking AI chats.
Google had removed this company’s extensions once before. On 24 July 2018, AdGuard published an investigation into the same company. Its browser extensions and mobile apps, with more than 11 million users together, sent the full address of each page their users visited to the company’s servers. Poper Blocker was one of them, with more than 2,280,000 users at the time.
By 25 July 2018, the apps and extensions were gone from the Chrome Web Store and Google Play. On 20 August 2018 the researchers added an update: “Most apps and extensions were reinstated, with seemingly little to no change.”
In September 2026, Dark Reading found that Poper Blocker’s publisher carries Google’s Established Publisher badge. That badge goes to publishers with “a consistent positive track record with Google services and compliance with the Developer Program Policy.” The reporters asked Google and Big Star Labs for a comment and got no answer from either.
In 2018, each captured request carried the value us=aeb204c39. The researchers back then took it for their own user ID. In 2026, the new researchers decoded one of Poper Blocker’s uploads and found the same value, "us": "aeb204c39", which they describe as a hardcoded sid, a fixed code built into the extension.
The URL still goes out in a field called u, the extension version in a field called nid. Eight years apart, it is the same identifier with the same two field names, now with an interpreter on top.
The same company has a second extension in the store. CrxMouse, a mouse gesture extension with 700,000 users, takes its instructions from the same server and also sends out the addresses its users visit.
Adblockers can see each address you open, because they need it to decide what to block. The researchers found that 1 in 5 adblockers with more than 100,000 users sends some form of browsing history out.
What to do:
- โ Open
chrome://extensions, oredge://extensionsin Edge, and look for Poper Blocker or “Pop up blocker for Chrome”. The Chrome ID isbkkbcggnhapdmkeljlodobbkopceiche, the Edge ID isbaplddocidbpmmneofgnhkjojmibmpck. - โ Remove it. The uninstall sends your last five domains one more time, and after that the collecting stops.
- โ Check for CrxMouse too, from the same company, and remove it as well.
- โ Did you paste passwords, API keys or code with secrets into an AI chat on a browser with Poper Blocker? Replace those keys and change those passwords.
- โ Do not treat the Featured badge as a safety check. Poper Blocker kept it after the warning in May.
- โ Before you install an extension, read the privacy section on its store page and the privacy policy it links to. The sale of personal data from this extension is written down in its own policy.
In my course you learn to capture and read network traffic with Wireshark, so you can see which servers your own machine talks to. My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.
โ Join my complete ethical hacking course
Hacking is not a hobby but a way of life.
Sources:
Am I Being Pwned: Poper Blocker, the adblocker that spies on you | AdGuard: Big Star Labs spyware campaign
Stay updated
Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.