Last week, Spotify halted a campaign for a malvertising operation that affected its customers who were registered as free subscribers. Specifically, it bombarded them with annoying pop-up windows that tried to promote malicious software.
The first signs that something was wrong appeared on Tuesday, October 4, when users complained on the Spotify forum. A day later, some reports also appeared on Twitter.
Users reported that the Spotify client application would unexpectedly open the browser to a specific URL that displayed a pop-up window. The pop-up window attempted to lure users into downloading a software package that contained malware.
The complaints came from Linux, Mac, and Windows users. The issue appeared only for Free Spotify users, which allows users to listen to a limited set of songs, with the agreement that the company may display ads periodically.
A day later, Spotify narrowed down the source of the problem to a series of malicious ads.
«We have identified an issue where a small number of users were experiencing a problem with some ambiguous-quality pop-ups in their default browsers as a result of an isolated issue with an advertisement in the free version. We have now pinpointed the source of the problem and have terminated its operation. We will continue to monitor the situation. If you see this issue again, please let us know the exact date and time in this thread».
Events like these had occurred before to Spotify free users and Spotify is not the only online service affected by malvertising campaigns.
While ad-blocking browser extensions harm the online economy and the revenue flow of small websites, they also constitute the only known ways by which users can block online malvertising campaigns.
Unfortunately, ad blockers cannot protect Spotify users. If the mysterious pop-ups persist, users should uninstall the Spotify client until the issue is resolved.

