Is Stacker - Falling tetra blocks! safe?
Stacker - Falling tetra blocks! fetches ad content from a remote server and injects it as raw HTML into the extension popup, and opens background tabs on install and update.
On install and update events, the extension retrieves a list of URLs from k-ext.pages.dev and opens each as an inactive background tab — the set of URLs opened is entirely controlled by the remote server. The extension popup also fetches an HTML fragment from the same remote server and inserts it directly into the DOM via innerHTML with no sanitization or integrity check, allowing the ad server to inject arbitrary markup into the popup.
Who publishes itKris10ansn - 1 other listing from the same operator, none carrying a finding
Kris10ansn - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 400k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension opens background tabs to server-supplied URLs on install
Installing or updating Stacker contacts a remote server (k-ext.pages.dev) for a list of URLs, then opens each as a non-active background tab, unprompted.
The list is entirely server-determined.
Confirmed on a fresh install of v2.2.40.
You install the Stacker extension or update it to a new version.
The background service worker fetches a URL list from a remote server and opens each URL as a background tab without showing them in the foreground.
The server determines which websites are opened on every user's device at install or update time. Any URL the server returns is loaded as a non-active background tab without displaying it in the foreground.
| When | You did | Extension did |
|---|---|---|
| On install | user You install the Stacker extension for the first time. | service_worker Service worker GETs k-ext.pages.dev/tetrys-install-urls and opens each returned URL as a background tab. |
| On update | user Chrome automatically updates the Stacker extension to a new version. | service_worker Service worker GETs k-ext.pages.dev/tetrys-update-urls and opens each returned URL as a background tab. |
Service worker fetches URL list and opens each entry as a background tab
var A = function(n) {
return _(n) // GET https://k-ext.pages.dev/{n}
.then((function(n) {
return n.text() // read full response body
}))
.then((function(n) {
return n.split(",") // split CSV into array of URLs
}))
.then((function(n) {
return n.filter((function(n) { // keep only entries with 'https://'
return -1 !== n.indexOf("https://")
}))
}))
},var E = function(n) {
var t = n.endpoint,
e = n.eventName,
r = n.data;
return A(t).then((function(n) { // fetch URL list for this endpoint
n.forEach((function(n) {
(function(n) {
return chrome.tabs.create({
url: n,
active: false // tab opens in background, not foreground
})
})(n).catch((function(n) {
return S(n, "".concat(e, "_open_error"))
}))
}))
}))
},chrome.runtime.onInstalled.addListener((function(n) {
// ...
n.reason === T.INSTALL && E({
endpoint: "tetrys-install-urls", // GET /tetrys-install-urls on first install
eventName: "install_promotion"
})
n.reason === T.UPDATE && E({
endpoint: "tetrys-update-urls", // GET /tetrys-update-urls on every update
eventName: "update_promotion"
})
}))- k-ext.pages.dev
Primary server (Cloudflare Pages) supplying the CSV list of URLs to open as background tabs on install and update events.
- k-ext-ads.netlify.app
Fallback server (Netlify) used when the Cloudflare Pages primary host returns an error.
- custom-cursor-extension.com
Third-party extension promotion site, returned by the uninstall-urls endpoint, illustrating destinations the server can direct background tabs to.
Where it sends data
Destinations our analysis observed Stacker contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- k-ext-ads.netlify.app
Stacker sends data to k-ext-ads.netlify.app. No other extension we have analysed sends data here.
- k-ext.pages.dev
Stacker sends data to k-ext.pages.dev. No other extension we have analysed sends data here.