CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

BadBlocker

campaign · campaign:island-badblocker-adblock-youtube-extension

An 11M-user Chrome ad-blocker extension found one server call away from arbitrary JavaScript injection on any site (Island).

Coverage
1
first 2026-06-28 → last 2026-06-28
Latest activity
2026-06-28
Island: "BadBlocker"; an 11M-user Chrome ad-blocker is one server config change away from arbitrary…
Peak priority
notable
1 notable
Targets
finance
sectors: finance, public-sector · regions: europe
Sources cited
2
2 hosts

Story timeline

  1. 2026-06-28Island: "BadBlocker"; an 11M-user Chrome ad-blocker is one server config change away from arbitrary JavaScript on any site
    research
ATT&CK techniques (2 across 3 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • PersistenceSoftware Extensions
  • Credential AccessInput Capture
  • CollectionInput Capture

Persistence TA0003

T1176Software Extensions×1

Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access levels of the host application.

Evidence: 2026-06-28/island-badblocker-an-11m-user-chrome-ad-blocker-is-one-serve · ATT&CK page ↗

Credential Access TA0006

T1056Input Capture×1

Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture).

Evidence: 2026-06-28/island-badblocker-an-11m-user-chrome-ad-blocker-is-one-serve · ATT&CK page ↗

Collection TA0009

T1056Input Capture×1

Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture).

Evidence: 2026-06-28/island-badblocker-an-11m-user-chrome-ad-blocker-is-one-serve · ATT&CK page ↗

Entries about BadBlocker (1)

2026-06-28 · view entry permalink →

NOTABLE

Island: "BadBlocker"; an 11M-user Chrome ad-blocker is one server config change away from arbitrary JavaScript on any site

Island researchers documented (2026-06-25) a dormant but architecturally complete arbitrary-JavaScript-execution capability in "Adblock for YouTube" (11M+ installs) (Island, 2026-06-25; The Hacker News, 2026-06-25). The extension fetches config every 24 hours; a server-controlled scriptletsRules field can activate a "create-element" scriptlet that appends an externally-sourced <script> to the DOM via a TrustedTypes policy that bypasses the browser's own script-injection guard. Because the extension declares <all_urls> host permissions but only checks whether the string youtube.com appears anywhere in the URL (not as the hostname), a lure such as https://bank.example.com/search?q=youtube.com passes the check, so an injected script could run in authenticated banking, admin-panel or enterprise-SaaS sessions with full DOM and credential access (T1176 Browser Extensions; T1056 Input Capture). Island demonstrated a Salesforce-data-exfiltration PoC; no malicious payload was live at analysis time, but sister extensions were previously removed by Google for actual malware. Defender concepts: flag browser extensions making config-fetch HTTPS requests outside their declared purpose; audit <all_urls> extensions against business need; enforce extension allowlisting via browser management policy.

The extension contains the architectural ingredients for arbitrary JavaScript execution on any website, activated by a single server-side configuration change, without an extension update, without a store review, and without any visible sign that something has changed.

If server passes 'script' as element type with JavaScript content, code runs in page context with access to sensitive data

Island
research28 Jun 05:05Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • island.io1 (50%)
  • thehackernews.com1 (50%)