Poperblocker is shipping an interpreter for a custom scripting language with variables, loops and functions where the programs are downloaded from the vendor's server after installation. The language can read page content, request bodies and WebSocket frames, capture regions of the page as images, zip them, and upload them to a server-specified address.
When MV3 came around, Google explicitly banned this - but they're still getting away with it.
This entire setup feels more like malware than just greyware. Obfuscated C2 with a remote code interpreter to exfiltrate data, with sandbox detection isn't something you find in most extensions.
![]()
Poper Blocker: The Adblocker That Spies on You
Poper Blocker (2M+ users, featured, verified publisher) ships a remote-code interpreter that downloads its programs a day after install, fingerprints the browser to dodge review, and exfiltrates your full browsing history, AI chats and ad data. Google banned exactly this under MV3. It's still live.amibeingpwned.com
I used to use this specific extension long time ago, before uBO.
