Investigation identifies owner of 60+ browser extensions which engaged in a long-running ad fraud scheme and were removed as part of a Google crackdown in Feb
It was a weed that Google kept trying and failing to kill. — The browser extension MyPDF kept appearing and being removed from the Chrome Web Store.
Context & Ripple Effects
In February, Google swept more than 500 malicious Chrome extensions off the Web Store as part of a crackdown on a long-running ad fraud network likely affecting millions of users. What the removals did not answer was who was behind them — BuzzFeed News' investigation now puts a name to the operator of at least 60 of those extensions.
The reporting also explains why the crackdown felt like weeding rather than eradication: the MyPDF extension kept resurfacing on the store after each takedown. That resilience is consistent with a pattern researchers have documented repeatedly, from fake ad blockers hijacking browsers in 2018 to the cluster of 295 extensions with 80M users inserting ads into search results later in 2020.
First-order effects
- The identified owner now faces exposure that anonymous takedowns never produced — Google and potentially advertisers defrauded by the scheme know whose operation ran the 60+ extensions.
- Users who installed the affected extensions learn the fraud was not incidental but an organized, persistent business run by one actor across many storefront listings.
Second-order effects
- Google's repeated failure to keep MyPDF off the store puts pressure on its review and re-submission controls, since the same operator could relist under new identities faster than enforcement catches up.
- Advertisers paying for traffic funneled through these extensions have grounds to demand better attribution and refunds, shifting scrutiny onto the ad networks that bought the fraudulent inventory.
Third-order effects
- If naming operators becomes standard practice after mass takedowns, extension marketplaces move toward identity verification and stricter publisher vetting — raising the cost of running distributed ad fraud at scale.
- The whack-a-mole pattern across 2018's fake ad blockers and 2020's successive purges points toward browser vendors tightening extension permissions and APIs structurally, rather than relying on post-hoc removals.
The trend: Browser extension abuse is shifting from anonymous hit-and-miss schemes to identified, industrialized operations, forcing Google toward structural marketplace controls instead of reactive purges.