The short version
- Bay Area Labs reported the Poper Blocker extension to Google in May. It is still listed, with 2 million users and a Featured badge.
- Researchers say it captures full URLs, screenshots, location and AI chatbot conversations.
- It fetches code from a remote server, so what it does can change after it passed review.
- Check what your staff have installed, and prefer open-source extensions that collect nothing.
Bay Area Labs reported a Chrome extension called Poper Blocker to Google in May 2026, and Dark Reading covered the findings on September 28. As of this morning it is still in the Chrome Web Store: two million users, 4.8 stars from more than 81,000 reviews, carrying Google’s Featured badge. According to the research it captures the full URL of every page visited, screenshots, approximate location, cross-device identifiers, and conversations with AI assistants including prompts, responses and which model was used.
Why the AI part matters most
Browsing history leaking is bad. Staff AI conversations leaking belongs in a different category. People paste things into a chatbot they would never type into a search box: draft contracts, client details, financial figures, source code, the difficult email they are trying to word carefully. If your acceptable use policy drew a line around what may go into AI tools, an extension scraping those conversations steps straight over it, and neither the employee nor the AI vendor has done anything wrong.
Why store review did not catch it
The extension reportedly pulls code from a remote server rather than shipping all its behavior in the published package, so what it does can change after approval. Google did not respond to Dark Reading’s request for comment and the extension remains listed four months on. That is the factual position rather than a claim about intent, and the lesson holds either way: a store listing, a high rating and a Featured badge are not a security assessment.
An extension that downloads its instructions after installation has been reviewed once and can behave differently every day afterwards.
If you need extensions, choose them differently
Prefer open source, where the code can be inspected and the project has a reputation to lose. For popup and ad blocking on Chrome the maintained option is uBlock Origin Lite by Raymond Hill, since the original uBlock Origin stopped working in Chrome when Google ended Manifest V2 support. Firefox users can still run the full version. Both are open source and neither collects browsing data.
Open source is not a guarantee on its own. It means the code can be audited, not that anyone has. Watch for two things whatever the licence: copycats using near-identical names, a persistent problem around popular blockers, and ownership changes, since a well-behaved extension that quietly gets sold is a common way malicious code reaches a browser that already trusts it.
What to do this week
Find out what is installed. On managed machines that inventory is visible centrally through Chrome or Edge management; otherwise it is a two-minute check per machine at chrome://extensions. Poper Blocker also exists on Edge. Then allowlist: decide what is permitted and block the rest by policy, because every extension your staff install can read every page they open, including your CRM, your email and your banking.
Browser extensions are the least examined software in most companies. They install in one click, request permissions nobody reads, and sit there for years. The question is not whether this particular one is on your network. It is whether you could answer that right now without walking around the office.
Could you list every browser extension running in your business?
Most businesses cannot. PTSI can inventory what is installed across your fleet, remove what should not be there, and put extension allowlisting in place so it stays that way.


