Yesterday, Google , decided to remove two extensions from the Chrome Web Store. They were fully functional ad blockers. However, the company was informed by a researcher that the ad blockers were deceiving users more well-known and trusted extensions.
The two extensions that were removed are “AdBlock” by “AdBlock, Inc” and “uBlock” by “Charlie Lee.” In addition to exploiting the names of other extensions, the two ad blockers were also removed for using the “cookie stuffing” technique.

Cookie stuffing allows a website extension browser to add more information to a user's cookie. In effect, the user visits a site and receives a third-party cookie from a site unrelated to the one they visited.
The administrators of the two extensions modified files when users visited a site. These modifications allowed the administrators to collect a commission from payments that users might make on the sites they visited.
The two extensions could be activated on many popular sites, such as microsoft.com, teamviewer.com, linkedin.com, aliexpress.com, booking.com and others.
The researcher who discovered the malicious activity of ad blockers is Andrey Meshkov, co-founder and CTO of AdGuard. The researcher noticed that the cookie stuffing process started 55 hours after installation and stopped if users opened Chrome's Developer Tools.
Both extensions were based on the code of the original “AdBlock” extension.
Meshkov published his findings a few days ago. Google was notified of the security and removed the extensions in order to protect its users. In addition, the extensions were disabled in all user browsers. This was done in an effort to prevent future attacks on Chrome users. The risk was very high, as the two ad blockers were quite popular. The “AdBlock” extension had more than 800,000 installations and “uBlock” had over 850,000.
