Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Poper Blocker Chrome extension with 2 million users scrapes AI chats, researchers say

Bay Area Labs says a Featured pop-up blocker downloads hidden programs that collect browsing history and AI chatbot conversations, and supports screenshot commands its server could switch on.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Bay Area Labs says Poper Blocker, listed with 2 million Chrome users, exfiltrates full browsing history and AI chatbot conversations.
  • 2The researchers say the server holds back the data-collecting programs until about 24 hours after install, and the extension checks for automated testing, to slip past review.
  • 3The researchers say they reported it to Google in May; on September 29 it still carried a Featured badge.

The news

Poper Blocker, a pop-up blocking extension that the Chrome Web Store lists with 2,000,000 users, secretly collects users' browsing history and conversations with AI chatbots, security firm Bay Area Labs said in a report published September 28, 2026.

The extension appears in the store, run by Alphabet's (GOOGL) Google, as “Pop up blocker for Chrome™ - Poper Blocker.” When Tech CEO Daily checked the listing on September 29, it showed a 4.8-star rating from 81.6K ratings, a Featured badge, and an established publisher label stating that the publisher has no history of violations. The listing said the extension was last updated on September 21.

According to Bay Area Labs, the extension contains a hidden interpreter that downloads encoded instructions from a server at api.pbapi.xyz. The researchers said the server returned 40 of these programs when they requested them, but sent no data-collecting programs until about 24 hours after installation; they found no timer in the extension itself. The extension also checks for signs of automated browsers, such as those used in testing, which the researchers said is designed to avoid Google's review process.

Bay Area Labs said the programs capture full web addresses of pages visited, including query parameters, along with referrer information, browser fingerprints and identifiers that link a user across devices through Chrome sync storage. The interpreter also supports commands to screenshot parts of a page and upload the image to an address the server chooses, the researchers said, though the 40 programs live when they checked did not use the page-capture or file-upload commands. The server can change the programs at any time, they added.

The report says 23 of those programs target ChatGPT, Claude, Gemini and Google's AI Mode. According to Bay Area Labs, they collect the prompts users type, the models' full answers including code blocks, conversation titles, the model in use and the user's subscription plan. Uploads are obscured with ROT47 encoding, and the server can change where uploads go.

Bay Area Labs said Poper Blocker was reported to Google in May 2026, after the firm listed it among extensions that scrape AI chats, and that four months later it remained Featured and Verified. The report does not describe any response from Google or from the extension's developer.

The numbers

Users shown on Chrome Web Store listing
2,000,000
Store rating
4.8 stars from 81.6K ratings
Remote programs returned to researchers
40
Programs aimed at AI chat services
23
Delay before server sent data-collecting programs
About 24 hours after install
Ad blockers with 100k+ users leaking browsing history
1 in 5 (Bay Area Labs estimate)

Why CEOs should care

For CISOs, the AI angle changes the stakes. Many employees now use chatbots for work, and their prompts can include code, contract language or customer details. Bay Area Labs says this extension copies those prompts and the answers, including code blocks, along with the full address of every page a user opens, which can include internal tools and document links. An ad blocker installed by an employee on a work laptop can therefore become a channel for company data. Check whether Poper Blocker appears in your managed browsers, and remove it where it does.

The broader fix is to stop treating store badges as a security review. Bay Area Labs also said it found that 1 in 5 ad blockers with more than 100,000 users send some form of browsing history out. Enterprise browser management tools let IT block all extensions except an approved list. Security leaders should ask: do we have an extension allowlist, who approves additions, and do we recheck approved extensions after updates, since behavior can change long after installation?

For general counsel and privacy officers, the question is exposure. If the extension ran on devices used for regulated data, such as health records or customer financial details, legal teams may need to assess what was in the browsing history and AI chats of affected users.

The bigger picture

Browser extensions sit in a blind spot. They run inside the browser with broad access to page content, and many companies manage them loosely compared with installed software. Bay Area Labs said Google's Manifest V3 rules prohibit extensions from building interpreters that run remotely fetched code, and that Poper Blocker uses exactly that design. If the researchers are right, the case shows that store policy and review did not catch the behavior, which puts more of the burden on the companies whose employees use the browser.

What’s next

Watch for whether Google removes the listing or strips its Featured and established publisher labels, and whether the developer responds to the findings. Security teams can search logs for traffic to pbapi.xyz, the domain Bay Area Labs identified, and check endpoint inventories for the Chrome extension ID bkkbcggnhapdmkeljlodobbkopceiche.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Poper BlockerBay Area LabsGoogle Chromebrowser extensionsAI chatbots

Earlier coverage of Google

All Google coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.