/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google blocklisted two Chrome “SearchBlox” extensions with 200K+ installs, after discovery of a backdoor that can be used to steal Roblox credentials and assets

Ax Sharma / BleepingComputer :

BleepingComputer Ax Sharma

Context & Ripple Effects

This is the latest entry in a long-running pattern: Google has repeatedly purged the Chrome Web Store after researcher discoveries, from ad-blocker impostors hijacking browsers in 2018 to 106 credential-stealing extensions with 32M downloads in 2020 and a 295-extension ad-injection cluster with 80M+ users. What distinguishes this round is the target: rather than ad fraud or generic browsing data, the SearchBlox backdoor is aimed at Roblox credentials and in-game assets.

First-order effects

  • The 200K+ users who installed the two SearchBlox extensions face immediate risk of Roblox account takeover and loss of virtual assets, and need to remove the extensions and rotate credentials.
  • Google's blocklist action cuts off new installs instantly, but existing users are only protected if they notice the warning or read coverage like this.

Second-order effects

  • Roblox now has an external threat vector it does not control — its account-and-asset economy being harvested through a third-party browser store — pushing it toward stronger user-side protections and player warnings.
  • Each researcher-driven takedown raises pressure on Google to tighten Chrome Web Store review and permission gating, since reactive blocklisting keeps arriving only after mass installs accumulate.

Third-order effects

  • If the pattern holds, browser extension stores stay a recurring supply-chain attack surface where value shifts from ad fraud to game economies holding real monetary worth, forcing platform owners to treat extensions as a standing security program rather than episodic cleanups.

The trend: Malicious Chrome extensions are evolving from ad injection and history harvesting toward direct theft of high-value gaming accounts, keeping the Chrome Web Store on a cycle of researcher discovery followed by mass takedowns.

Discussion

  • @ax_sharma Ax Sharma on x
    NEW: Chrome extension ‘SearchBlox’ installed by 200,000+ Roblox users appears to have been compromised. #Backdoor attempts to steal Roblox creds and Rolimons assets. https://www.bleepingcomputer.com/ ... #malware #opensource https://twitter.com/...