Browser extension AI chat exfiltration Security researcher Arnott observed the Poper Blocker browser extension exfiltrating URLs using character-mapping obfuscation and gated AI-chat scraping that activated after a 24-hour user-ID age, according to an AmIBeingPwned report. Arnott also observed CrxMouse exfiltrating URLs with base64 obfuscation and carrying the same remote-config infrastructure, though he did not observe CrxMouse explicitly exfiltrating AI chats during testing. Both extensions are published by Big Star Labs LP, a name matching a Delaware-registered "Big Star Labs" entity that AdGuard's Andrey Meshkov documented in a July 24, 2018 investigation as collecting browsing histories from more than 11 million users via Chrome extensions and mobile apps; whether the 2026 Big Star Labs LP is the same legal entity is not established in cited sources. dropped url-status from 1 citation s with no available capture | ← Older revision | | Revision as of 13:48, 13 September 2026 | | | Line 89: | | Line 89: | | | | ===Big Star Labs LP=== | | ===Big Star Labs LP=== | | | Big Star Labs LP is the publisher of Poper Blocker & CrxMouse. Arnott observed Poper Blocker exfiltrating URLS