Google blocklisted two Chrome “SearchBlox” extensions with 200K+ installs, after discovery of a backdoor that can be used to steal Roblox credentials and assets
Ax Sharma / BleepingComputer :
Context & Ripple Effects
This is the latest entry in a long-running pattern: Google has repeatedly purged the Chrome Web Store after researcher discoveries, from ad-blocker impostors hijacking browsers in 2018 to 106 credential-stealing extensions with 32M downloads in 2020 and a 295-extension ad-injection cluster with 80M+ users. What distinguishes this round is the target: rather than ad fraud or generic browsing data, the SearchBlox backdoor is aimed at Roblox credentials and in-game assets.
First-order effects
- The 200K+ users who installed the two SearchBlox extensions face immediate risk of Roblox account takeover and loss of virtual assets, and need to remove the extensions and rotate credentials.
- Google's blocklist action cuts off new installs instantly, but existing users are only protected if they notice the warning or read coverage like this.
Second-order effects
- Roblox now has an external threat vector it does not control — its account-and-asset economy being harvested through a third-party browser store — pushing it toward stronger user-side protections and player warnings.
- Each researcher-driven takedown raises pressure on Google to tighten Chrome Web Store review and permission gating, since reactive blocklisting keeps arriving only after mass installs accumulate.
Third-order effects
- If the pattern holds, browser extension stores stay a recurring supply-chain attack surface where value shifts from ad fraud to game economies holding real monetary worth, forcing platform owners to treat extensions as a standing security program rather than episodic cleanups.
The trend: Malicious Chrome extensions are evolving from ad injection and history harvesting toward direct theft of high-value gaming accounts, keeping the Chrome Web Store on a cycle of researcher discovery followed by mass takedowns.