Is Adblock YouTube™ - Free Ad Blocker safe?

Medium risk

Adblock YouTube opens hidden affiliate tabs on ~11,000 partner sites, disguised to users as a tree-planting 'Eco Mode'.

The extension ships a bundled list of roughly 11,000 partner domains and watches every page you navigate to across your browser. When you land on a matching site, it opens a hidden, pinned background tab to an affiliate redirect link on go.script.green (closing it a couple seconds later) before you notice, generating referral revenue on your visit. Users are only shown a consent prompt framed as an environmental 'Eco Mode' that claims to plant trees and offset carbon emissions, with no mention of the affiliate redirects or referral income this actually produces.

Scripts Greenv0.4.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-506
SourceAI FOUND

Adblock YouTube opens a background tab to an affiliate network on partner sites

Code analysis shows that after you accept the 'Eco Mode' prompt, visiting any of about 12,000 bundled partner domains makes the extension open a background tab to a go.script.green affiliate link, then close it seconds later.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You visit a website that appears on the extension's bundled partner list.

This only starts after you previously clicked 'Allow' on the one-time 'Eco Mode' prompt.

The extension did this

The extension opens a new pinned background tab to a go.script.green affiliate redirect link for that site.

The tab never becomes active and closes itself about two seconds after it finishes loading.

02EvidenceCODE COMPARE
The code that does this

The global navigation listener and the tab it opens

What it actually does
Rate-limit check before opening a tabgreen/green_mode_bg.js:106-123
async function shouldTrackUrl(domain) {
	const match = domain && domainMap.has(domain);

	if (!match) {
		return false;
	}

	const result = await chrome.storage.local.get(domain);
	const timestampFromPreviousTabOpening = result[domain];

	if (!timestampFromPreviousTabOpening) {
		return true;
	}

	const minutes = 60;

	return hasMinutesPassed(timestampFromPreviousTabOpening, minutes);
}
The chrome.tabs.onUpdated listener, active on every tabgreen/green_mode_bg.js:135-162
function setupUrlChecking() {
	if (tabUpdateListener) {
		chrome.tabs.onUpdated.removeListener(tabUpdateListener);
	}

	tabUpdateListener = async (tabId, changeInfo, tab) => {
		const applyListener = await shouldListenerBeAppliedOnThisTab(tabId);

		if (!applyListener) {
			return;
		}

		if (changeInfo.status === 'complete') {
			const domain = getDomainFromUrl(tab.url);
			const shouldTrack = await shouldTrackUrl(domain);

			if (shouldTrack) {
				const affiliateData = domainMap.get(domain);
				if (affiliateData && affiliateData.affiliate_url) {
					openTabAndSaveStatus(affiliateData.affiliate_url, domain);
					maybeShowTabOpenedPopup(tabId);
				}
			}
		}
	};

	chrome.tabs.onUpdated.addListener(tabUpdateListener);
}
Opening the affiliate tab and scheduling its removalgreen/green_mode_bg.js:168-201
function openTabAndSaveStatus(url, domain) {
	chrome.storage.local.set({ [domain]: Date.now() });

	const millisecondsToWaitBeforeClosingTab = 2000;

	chrome.tabs.create({ url: url, active: false, index: 10, pinned: true }, (tab) => {
		chrome.storage.local.set({ tempTabId: tab.id }, () => {
			function removeTabAfterFinishLoading(tabId, changeInfo) {
				if (tabId === tab.id && changeInfo.status === 'complete') {
					setTimeout(() => {
						chrome.tabs.get(tabId, () => {
							chrome.tabs.onUpdated.removeListener(removeTabAfterFinishLoading);
							chrome.storage.local.remove('tempTabId');

							if (chrome.runtime.lastError) {
								return;
							}

							chrome.tabs.remove(tabId);
						});
					}, millisecondsToWaitBeforeClosingTab);
				}
			}

			chrome.tabs.onUpdated.addListener(removeTabAfterFinishLoading);
		});
	});
}
03EvidencePLAIN NOTE
What the 'Eco Mode' prompt tells you

The one-time prompt, titled 'Adblock in Eco Mode?', says it 'will not interrupt your browsing.' The follow-up popup calls it a partner site and talks about planting trees; neither mentions affiliate links or ad revenue.

04EvidenceTHIRD PARTY LIST
Where the background tab points
  • go.script.green

    Affiliate redirect link opened in the background tab for every matching partner site; the redirect target is unique per partner domain.

  • scripts.green

    Destination of the 'Learn more' link shown in both the install and in-page popups; uses the same 'Green Mode' branding as the redirect host above.

05EvidenceARTIFACT
Check if you're affected

Loads the extension's bundled partner map and reports whether a given domain would trigger a background affiliate tab, and which redirect link it maps to.

RequiresPython 3.8+
check_partner_match.py · py
#!/usr/bin/env python3
"""
check_partner_match.py

Checks a domain against Adblock YouTube's bundled green/partners.json
affiliate map, the same file the extension's background service worker
loads on startup, and reports the go.script.green redirect it maps to.

Usage:
    python3 check_partner_match.py partners.json example.com
"""
import json
import sys
from urllib.parse import urlparse


def strip_www(host):
    return host[4:] if host.startswith("www.") else host


def load_partner_map(partners_path):
    with open(partners_path, "r", encoding="utf-8") as fh:
        entries = json.load(fh)

    domain_map = {}
    for item in entries:
        host = urlparse(item["partner_url"]).hostname
        if host:
            domain_map[strip_www(host)] = item["affiliate_url"]
    return domain_map


def main():
    if len(sys.argv) != 3:
        print("usage: check_partner_match.py <partners.json> <domain>")
        sys.exit(1)

    partners_path, domain = sys.argv[1], strip_www(sys.argv[2].lower())
    domain_map = load_partner_map(partners_path)

    print(f"Loaded {len(domain_map)} unique partner domains from {partners_path}.")
    if domain in domain_map:
        print(f"MATCH: visiting {domain} would open a background tab to {domain_map[domain]}")
    else:
        print(f"No match: {domain} is not in the bundled partner list.")


if __name__ == "__main__":
    main()
How to run it
  1. 1
    Copy green/partners.json out of the extension's extracted files.
  2. 2
    Run: python3 check_partner_match.py partners.json example.com.
  3. 3
    Try your own frequently visited sites.
06EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 0.4.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

Where it sends data

Destinations our analysis observed Adblock YouTube™ - Free Ad Blocker contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • go.script.green

    Adblock YouTube™ - Free Ad Blocker sends data to go.script.green. No other extension we have analysed sends data here.

Updated 30 September 2026plpmbnkaeofcepeodppobhjncgcjpllm