Yaamlabs
Threat intel

Poper Blocker ad blocker caught collecting AI chats

A Chrome and Edge pop-up blocker with 2 million users pulls remote code that copies ChatGPT, Claude and Gemini chats. How to find it, remove it and rotate secrets.

By Yaali. October 9, 2026, 7 min read, Threat intel, AI security, Identity.

Cover illustration of a browser window with a shield-shaped plug-in sending chat bubbles along thin threads to a distant server, with the Yaamlabs logo and the text: An ad blocker that reads your AI chats, 2M+ Chrome users, still listed Oct 1

Poper Blocker, a pop-up and ad blocker sold as "Pop up blocker for Chrome" with about 2 million users and a 4.8 star rating, copies its users' conversations with ChatGPT, Claude, Gemini and Google AI Mode, along with the full address of every page they visit. James Arnott of Bay Area Labs, which runs the Am I Being Pwned extension-risk service, published the analysis on September 28, 2026. The same extension is listed for Microsoft Edge and, according to the researchers, takes its instructions from the same server.

Bay Area Labs says it reported Poper Blocker to Google in May, and the listing was still live with its Featured badge on October 1. If your staff use AI chat assistants in Chrome or Edge on company machines, anything they typed or pasted there, including source code, customer records and API keys, may have left the building through a browser extension your security tools treat as harmless.

How Poper Blocker collects: the user accepts data sharing, the extension fetches programs from api.pbapi.xyz, collection starts about 24 hours after install with 23 of 40 programs aimed at AI chats, and uploads go to the operator's server with a cross-device ID. Data seen collected: AI conversations, account details, browsing history and a browser fingerprint

How it works

An extension allowed to read and change data on all websites sees whatever a page shows, including a chat window. Chrome Web Store review looks at the code inside the package, and Poper Blocker keeps its collection code on a server instead.

The package contains an interpreter for a small custom scripting language with variables, loops and functions, but no collection logic. On startup the extension sends a POST request to https://api.pbapi.xyz/v2/rec and gets back a batch of programs, and a second call to /v2/config returns a dictionary that maps numbered commands to their meaning. The command names never appear in the extension's code, so a reviewer reading the package sees an interpreter and a list of numbers. The programs can read page content, HTTP request and response bodies and WebSocket frames, capture parts of the page as images, compress what they gather and upload it to whatever address the server names.

When the researchers first installed the extension, the server returned no collection programs. They arrived about 24 hours later, and the researchers found no timer in the extension that would explain the delay, so the server decides. The researchers read the delay as a way to outlast the short sandbox runs used in store review. One program runs on every site and reports navigator.webdriver, ChromeDriver and Playwright markers and headless-browser signs, so the operator can also hold collection back from analysis machines.

On the capture date the server sent 40 programs, and 23 targeted AI chat services. They collected prompts, full responses, "thinking" traces, conversation titles, the model in use and the user's subscription plan. The Claude program read the full response body from the conversation API. Other programs took complete URLs with query strings and referrers for every page, plus advertising and social media content. Every upload carries a UUID stored in Chrome sync storage, which, with Chrome sync on, follows the user to every browser signed in to the same Google account.

The interpreter also supports full-page screenshots and file uploads. Gridinsoft, reviewing the same findings, notes that none of the 40 programs captured on that day used them, and the keylogging shown in the report was a lab demonstration with the researchers' own program. Collection also depends on a consent popup that reappears on every page until the user accepts "Disclosing to Affiliates" and "Disclosing to Third Parties", with advanced blocking features tied to agreeing. The operator, Big Star Labs, says in its privacy policy that it processes AI inputs and outputs and that some data may be sold to affiliates, who can resell it to business customers.

What attackers are doing

The operator is a company running a data business, and that shapes the response. Nobody has to break in: the data goes to the operator by design, and its policy permits resale. Once a developer's pasted database password reaches an affiliate or one of its business customers, you have no say in what happens to it.

The researchers queried the server with one install identifier on one day, so they cannot show which users received which programs or whether collection differs by country or install date. The server can change the programs, the upload destination and the automation checks at any time without a new extension release. A clean result on a test machine today therefore says little about what a user's browser did last month.

Poper Blocker is the largest of the ad blockers caught doing this so far in 2026. In June, MalExt Sentry reported two smaller ad blockers, Smart Adblocker and Adblock for Browser, recording AI chats from roughly 90,000 users. In December 2025, Koi Security found Urban VPN and related extensions harvesting chatbot conversations from more than 8 million people.

What to do

Response steps for Poper Blocker: find it with the Chrome Enterprise Core or Defender extension inventory or a file sweep, force removal by policy, check DNS and proxy logs for pbapi.xyz and ask users which chats held sensitive data, then rotate pasted secrets

1. Find it

The identifiers are bkkbcggnhapdmkeljlodobbkopceiche for Chrome and baplddocidbpmmneofgnhkjojmibmpck for Edge.

  • In the Google Admin console with Chrome Enterprise Core, open the Apps and extensions usage report under Chrome browser and search for the Chrome ID. It lists the browsers and profiles where it is installed.
  • With Microsoft Defender Vulnerability Management, the browser extensions inventory under Inventories shows Edge and Chrome extensions per device.
  • Without either, sweep endpoints for a folder with the ID name under %LOCALAPPDATA%\Google\Chrome\User Data\<profile>\Extensions\ and %LOCALAPPDATA%\Microsoft\Edge\User Data\<profile>\Extensions\. Check every profile, not only Default.

2. Remove it by policy

For Chrome, set the ExtensionSettings policy with {"bkkbcggnhapdmkeljlodobbkopceiche": {"installation_mode": "removed"}}. Google's documentation says removed uninstalls the extension where it is already present and stops reinstallation, while blocked only stops new installs. Add the Edge ID the same way in Edge's ExtensionSettings, or list it under HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallBlocklist as value 1. Microsoft says a blocklisted extension already installed is disabled and the user cannot enable it again. The matching Chrome key is HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallBlocklist. Confirm on a test machine at chrome://policy or edge://policy.

If you cannot push browser policy today, block pbapi.xyz and its subdomains at DNS and the web proxy. This cuts off the program download and the default upload address, but the server can name a different destination in any response, so treat it as a stopgap.

3. Check what was exposed

Search DNS, proxy and firewall logs for pbapi.xyz to find machines that ran the extension and to date the first contact. According to the researchers, uploads are encoded, so a data loss prevention (DLP) tool inspecting traffic will not see readable chat text in them. That makes the conversation history in the AI service the better record. Ask each affected user to review their ChatGPT, Claude and Gemini history for the period the extension was installed and list chats that held code, customer data, internal URLs or credentials.

4. Rotate and clean up

Treat any secret that appeared in those chats as disclosed: API keys, cloud access keys, personal access tokens, database connection strings, webhook URLs and passwords. Revoke and reissue them, then check the issuing service's audit log for use since the extension was installed. Removing the extension stops future collection and does nothing about data already uploaded.

The wider lesson

Store badges and ratings did not protect anyone here: Poper Blocker kept its Featured badge four months after it was reported. Most organisations still let users install any extension. An allowlist model, with ExtensionInstallBlocklist set to * and approved IDs in ExtensionInstallAllowlist, turns a story like this into a short check instead of an incident. Pair it with a rule that secrets never go into AI chats, and give developers an approved way to share them.

Our safeguarding and hardening work sets up browser extension allowlists and policy for Chrome and Edge fleets, and our security operations team can run the inventory and log checks above across your estate. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Bay Area Labs, Am I Being Pwned, SecurityWeek, Dark Reading, Gridinsoft, Mallory, Chrome Web Store listing, Google Chrome Enterprise ExtensionSettings help, Microsoft Edge ExtensionInstallBlocklist policy, Cybersecurity News on PromptSnatcher, The Register on Urban VPN, Nudge Security on Urban VPN.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.