Is Stacker - Falling tetra blocks! safe?

Medium risk

Stacker - Falling tetra blocks! fetches ad content from a remote server and injects it as raw HTML into the extension popup, and opens background tabs on install and update.

On install and update events, the extension retrieves a list of URLs from k-ext.pages.dev and opens each as an inactive background tab — the set of URLs opened is entirely controlled by the remote server. The extension popup also fetches an HTML fragment from the same remote server and inserts it directly into the DOM via innerHTML with no sanitization or integrity check, allowing the ad server to inject arbitrary markup into the popup.

Kris10ansnv2.2.44Chrome Web Store
45Risk
Who publishes it

Kris10ansn - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Kris10ansn

Same store account

1 other listing published from this account, 400k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Extension opens background tabs to server-supplied URLs on install

Installing or updating Stacker contacts a remote server (k-ext.pages.dev) for a list of URLs, then opens each as a non-active background tab, unprompted.

The list is entirely server-determined.

Confirmed on a fresh install of v2.2.40.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the Stacker extension or update it to a new version.

The extension did this

The background service worker fetches a URL list from a remote server and opens each URL as a background tab without showing them in the foreground.

The server determines which websites are opened on every user's device at install or update time. Any URL the server returns is loaded as a non-active background tab without displaying it in the foreground.

02EvidenceCORRESPONDENCE
Both install and update events trigger remote URL fetches that open background tabs
WhenYou didExtension did
On install
user
You install the Stacker extension for the first time.
service_worker
Service worker GETs k-ext.pages.dev/tetrys-install-urls and opens each returned URL as a background tab.
On update
user
Chrome automatically updates the Stacker extension to a new version.
service_worker
Service worker GETs k-ext.pages.dev/tetrys-update-urls and opens each returned URL as a background tab.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://k-ext.pages.dev/tetrys-install-urls
Server returned HTTP 200 with a comma-separated URL list (observed during dynamic analysis on fresh install). Each URL containing 'https://' is opened as a background tab. A parallel request to /tetrys-uninstall-urls returned 'https://custom-cursor-extension.com/webstore?s1=mw&s2=k&s3=uninstall&s4=stacker', illustrating the format and third-party nature of server-controlled redirect targets.
04EvidenceCODE COMPARE
The code that does this

Service worker fetches URL list and opens each entry as a background tab

What it actually does
A() — fetches endpoint, splits comma-separated response into URL listdeobfuscated/background-bundle.js:374–384
var A = function(n) {
  return _(n)                          // GET https://k-ext.pages.dev/{n}
    .then((function(n) {
      return n.text()                    // read full response body
    }))
    .then((function(n) {
      return n.split(",")                // split CSV into array of URLs
    }))
    .then((function(n) {
      return n.filter((function(n) {     // keep only entries with 'https://'
        return -1 !== n.indexOf("https://")
      }))
    }))
},
E() — opens a background tab for every URL in the listdeobfuscated/background-bundle.js:386–406
var E = function(n) {
  var t = n.endpoint,
    e = n.eventName,
    r = n.data;
  return A(t).then((function(n) {      // fetch URL list for this endpoint
    n.forEach((function(n) {
      (function(n) {
        return chrome.tabs.create({
          url: n,
          active: false               // tab opens in background, not foreground
        })
      })(n).catch((function(n) {
        return S(n, "".concat(e, "_open_error"))
      }))
    }))
  }))
},
onInstalled listener — wires install and update events to E()deobfuscated/background-bundle.js:517–531
chrome.runtime.onInstalled.addListener((function(n) {
  // ...
  n.reason === T.INSTALL && E({
    endpoint: "tetrys-install-urls",    // GET /tetrys-install-urls on first install
    eventName: "install_promotion"
  })
  n.reason === T.UPDATE && E({
    endpoint: "tetrys-update-urls",     // GET /tetrys-update-urls on every update
    eventName: "update_promotion"
  })
}))
05EvidenceTHIRD PARTY LIST
Servers that control which URLs are opened on install and update
  • k-ext.pages.dev

    Primary server (Cloudflare Pages) supplying the CSV list of URLs to open as background tabs on install and update events.

  • k-ext-ads.netlify.app

    Fallback server (Netlify) used when the Cloudflare Pages primary host returns an error.

  • custom-cursor-extension.com

    Third-party extension promotion site, returned by the uninstall-urls endpoint, illustrating destinations the server can direct background tabs to.

Where it sends data

Destinations our analysis observed Stacker contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • k-ext-ads.netlify.app

    Stacker sends data to k-ext-ads.netlify.app. No other extension we have analysed sends data here.

  • k-ext.pages.dev

    Stacker sends data to k-ext.pages.dev. No other extension we have analysed sends data here.

Updated 30 September 2026bnchicpgbdgahiecgofdabidjihblaff