TL;DR
On 22 September I typed kiwi.com into a clean browser and pressed Enter. I clicked nothing. I never reached Kiwi.
Chrome’s own network log shows it made no request to kiwi.com at all. A cashback extension rewrote the navigation before anything left the browser, sent it through two intermediaries and into a Chinese affiliate network, where the affiliate link had expired. The journey ended on an error page.
The extension is Cashback Master. It has 100,000 users. It is in the Chrome Web Store today. And on a clean install it can arrive with the redirecting already switched on, which is not what its store listing says. Whether it does is decided by a server after you install it, not by anything in the package Google reviewed, and the answer changes.
The Test
A brand new Chrome profile. No accounts signed in. One extension installed. VPN to San Francisco.
That last detail turns out to matter, though not in the way I first thought. I will come back to it.
I ran it twice, typing the same address both times.
Control, extension disabled, 08:19:47. kiwi.com → https://www.kiwi.com/en/. Arrived normally.
Test, extension enabled, 08:23:57. I never arrived at all.
The difference is not a matter of interpretation. Chrome has a built-in packet logger at chrome://net-export, and I ran it for both. The counts:
| Requests to kiwi.com | Requests to cbmaster.pro | |
|---|---|---|
| Control, extension disabled | 67 | 2 |
| Test, extension enabled | 0 | 7 |
Sixty-seven requests to Kiwi with the extension off. Zero with it on.
This is the part worth sitting with. It isn’t a redirect that happened after reaching the merchant and rewrote the credit. The merchant was never contacted. The extension’s rule intercepted the navigation inside the browser, so the first thing Chrome sent to the internet went to l.cbmaster.pro.
Where It Actually Went
1. http://kiwi.com/ ← what I typed
2. https://l.cbmaster.pro/?subid=master_cb&surl=https%3A%2F%2Fkiwi.com%2F
&durl=…showmelinks.com…chinesean.com/affiliate/clickBanner.do
?wId=67376%26pId=21677%26cId=36170
3. https://showmelinks.com/en/site/goto?id=1790065435
4. https://showmelinks.com/?rl=…chinesean.com/affiliate/clickBanner.do…
5. https://www.chinesean.com/affiliate/click.do?nocscript=true
&finalCookieId=NEW_FD49B2769073C579529E850E1998&txId=be1a0c836ebf7
6. https://www.chinesean.com/affiliate/clickBanner.do?wId=67376&pId=21677&cId=36170
7. https://www.chinesean.com/affiliate/expired.jsp ← "Expired"
Four seconds, start to finish. The affiliate link was dead, so instead of arriving at a travel booking site I arrived at an affiliate network’s expired-link page.
In my last article, I wrote about commission being paid on a customer the merchant already had. This is worse and simpler. Kiwi didn’t pay commission on this visit, because no sale happened. They just lost the customer.
The expired link is the only reason any of this was visible. When the link works, you arrive at the merchant normally, the page looks exactly as it should, and the only thing that has changed is that someone now has a commission claim on a purchase they had nothing to do with. That is the ordinary case. This was simply the version that failed loudly enough to notice.
Chrome Names the Culprit
Two things the network log records that no amount of argument gets round.
The first is attribution. The log contains:
URL_REQUEST_START_JOB POST https://cbmaster.pro/update_user_settings
"initiator": "chrome-extension://ejcfngdpgojodfjcajnglnhppglcfedg"
That extension ID is Cashback Master’s. The browser itself recorded which piece of software made the request.
The second is that I typed it. The log contains Chrome’s omnibox autocomplete requests, one per keystroke: q=kiwi, q=kiwi., q=kiwi.c, q=kiwi.co, q=kiwi.com. There was no link. There was no coupon popup. There was a person typing an address.
It Arrives Switched On, and Somebody Else Controls the Switch
Update, 29 September 2026. When I published this on 28 September, this section said the behavior depended on which country you installed from. That was my explanation for what I observed on the 24th, and it was wrong.
The observation has not changed. Two clean profiles, thirteen minutes apart, one arriving disabled with no rules and the other arriving enabled with the full set. That happened, and the evidence is below.
What changed is what I can conclude from it. Today I asked the extension’s own configuration endpoint from both connections, the Bangkok one and the San Francisco one. Both return the enabled setting and the same rule list. Whatever produced the difference on the 24th is not producing it now, and I cannot tell a reader what happens when they install this from outside the United States.
The durable finding is the one underneath, and it is worse: the switch is not in the extension at all. It is an answer from a server, given per request, and it moved within five days.
Cashback Master’s Chrome Web Store listing says, under Key Features:
“Auto-Cashback feature available — enable it in extension settings to activate cashback automatically”
And under How it works:
“Enable Auto-Cashback in the settings for hands-free savings every time you buy online.”
Both describe something the user turns on.
On 22 September I installed the extension into a clean profile, over the San Francisco connection, and before opening the settings panel and before visiting any website I read its stored configuration:
user_settings = {"auto_cashback_enabled": true}
It arrived enabled.
Two days later I repeated that on my own connection in Bangkok, and it arrived disabled. Same version. Same clean-profile method.
There were two differences between those runs: the date, and where I appeared to be. So I ran both again, thirteen minutes apart on the same machine, changing only the connection.
| 24 September 2026 | Bangkok, my own connection | San Francisco, via VPN |
|---|---|---|
| Installed | 15:34 | 15:47 |
| Extension version | 1.0.0.2 | 1.0.0.2 |
auto_cashback_enabled |
false | true |
| Redirect rules loaded | 0 | 4,495 |
| Data stored on disk | 89 KB | 3.3 MB |
Two fresh profiles, one machine, one browser, one version of one extension, a quarter of an hour apart, arriving in completely different states. One with nothing enabled and no rules. The other with instructions to intercept navigations to thousands of domains already loaded.
I took that to mean the behavior depended on where you were. Five days later that turned out to be wrong.
What the pair does establish is that two clean installs of the same version can arrive in opposite states minutes apart, and that whatever decides which, it is not the user, it is not the package, and it is not visible to either.
The extension’s own code shows where the decision is made. On start-up it generates a random 32-character identifier, then asks two questions of its own server:
https://cbmaster.pro//1.0.0.2/user_settings
https://cbmaster.pro/master_cb//1.0.0.2/shops.json
The first returns whether auto-cashback is on. The second returns the redirect rules. Whatever comes back is written straight into the extension’s storage. Because the identifier is generated by the extension rather than issued by the server, anyone can ask those two questions without installing anything at all, which is how I checked it again today.
I am describing what it does, not why. But the shape of it is worth stating plainly. An extension whose behavior is decided per request, on a server, can be one thing when somebody looks at it and another thing the rest of the time. None of that is in the package, and the package is the only part anybody reviews.
For contrast, its sibling Cashback Ninja stores false on a clean install, and its privacy policy states plainly that auto-cashback is switched off by default. One of these two extensions does what it says. The other’s answer depends on what its server says that day.
Nearly 4,000 Merchants, Before You Visit Anything
The same clean profile, on the US connection, already contained 4,494 redirect rules covering at least 3,973 distinct domains, loaded before I had browsed anywhere. Each is a fully formed instruction:
"action": {"redirect": {"url": "https://l.cbmaster.pro/?subid=master_cb&surl=…"}}
"condition": {"requestDomains": ["100percentpure.com"], "excludedInitiatorDomains": […]}
"id": 2181, "priority": 1
The domains include 1800flowers, 1800contacts, 1Password, 123inkjets and 1688, alongside a long tail of gambling sites.
I say “at least” because rules can match in more than one way, and counting only the ones that name a domain outright undercounts the list. The true figure is higher.
None of this is in the package Google reviewed. The extension’s manifest declares no rules at all. They arrive from cbmaster.pro after installation and are registered as session rules, which Chrome discards when you close the browser and which the extension rebuilds the next time it starts. Nor is the switch that decides whether any of it runs. That is answered by the same server, on the same visit.
The listing does say “thousands of online stores”, so the scale itself is not a misrepresentation. What the listing doesn’t convey is the mechanism: these are not offers presented to you when you arrive somewhere. They are standing instructions to intercept your navigation to thousands of domains before the browser contacts any of them.
Two Extensions, One Server
Cashback Ninja and Cashback Master are published under different developer names, with different signing keys, different privacy policies, and different store listings. Between them they have 160,000 users.
Four commands, which anyone reading this can run:
nslookup cashbackninja.top 8.8.8.8 → 3.10.43.234
nslookup cbmaster.pro 8.8.8.8 → 3.10.43.234
nslookup tp.cashbackninja.top 1.1.1.1 → 35.84.115.54
nslookup tp.cbmaster.pro 1.1.1.1 → 35.84.115.54
Same application server. Same tracking server. Two different public resolvers, same answers.
3.10.43.234 is an Amazon EC2 instance in London. It is a single-tenant cloud address, not shared hosting and not a CDN. A reverse lookup returns eleven domains on it, most last resolved on 10 August 2026. Among them: cashbackninja.su, t-cashback.xyz, and alicoupon.site, which is notable because Cashback Master’s store listing gives its developer as “Ali Cupons”.
The rest of that server hosts Russian-language download and betting sites.
The Roster
Each extension has its own tp. tracking subdomain on the second server. That makes the list of them a roster, and there are more than two:
tp.cashbackninja.top → 35.84.115.54
tp.cashbackninja.su → 35.84.115.54
tp.cbmaster.pro → 35.84.115.54
tp.vkdownloader.ru → 35.84.115.54
tp.ad-blocker.space → 35.84.115.54
That last one is an ad blocker. A different category of product entirely, installed by people who are specifically choosing to control what runs in their browser.
Its apex domain no longer resolves, and the Wayback Machine has no snapshot of it. Its tracking endpoint is still live. I could not find the extension in the Chrome Web Store, and I am not going to tell you what it did, because I don’t know.
What I Am Not Claiming
I don’t know who operates these. The domains are behind privacy protection. Shared infrastructure is strong evidence that the two extensions are run together. It is not a company register entry, and I am not asserting ownership.
I don’t know what decides the switch. On 24 September a Bangkok install arrived disabled and a San Francisco install arrived enabled, thirteen minutes apart. On 29 September both connections returned enabled. Geography was my first explanation and it did not survive the second test. It could be location, a rollout, a cohort, or something I have not thought of. What I can show is that the decision is made on their server, and that it moves.
Something changed after I published, and I cannot tell you why. I wrote to both developers on 22 September, and my San Francisco results on the 22nd and the 24th were identical, so nothing moved when they first heard from me. Between the 24th and the 29th the answer served to my Bangkok connection changed from disabled to enabled. I published on the 28th. I have no way to connect those two facts and I am not going to imply one.
They are not identical. Cashback Master’s install carried 4,494 rules across at least 3,973 domains. Cashback Ninja’s carried 90 rules across 14. That may reflect what each had fetched rather than a designed difference, and I am reporting what I observed rather than what I assume.
Cashback Ninja is honest about its default. It ships auto-cashback off and says so. My criticism of the default state applies to Cashback Master alone.
One developer has a removed extension. “Ali Cupons” previously published an AliExpress coupon tool, delisted on 31 August 2026. Its archived manifest is Manifest V2, narrowly scoped and last updated in 2022. That looks like the Manifest V2 sunset, not enforcement, and it would be misleading to present it as Google acting against them.
I Checked Sixteen Others
To find out whether this is simply what shopping extensions look like, I downloaded and inspected sixteen more: FatCoupon, TopCashback, ShopBack, Cently, Coupert, LetyShops, Cashback Monitor, Cashback Comparison, Cashback Assistant, Troywell, Hyyzo, Adblock for Youtube, and several AliExpress coupon tools.
I have published the tool I used to do it. crx-fingerprint downloads an extension’s package from Google’s own update endpoint and reports its permissions, its content scripts and every external host hardcoded in its code, without installing it and without running any of it. It is a single Python file with no dependencies, under an MIT licence. Every count in this section can be reproduced by anyone who wants to check it.
Two of the sixteen request declarativeNetRequestWithHostAccess, the permission that allows an extension to rewrite and redirect network requests: Troywell, and Cashback Assistant, which turns out to be Opera’s. A third, Adblock for Youtube, requests Chrome’s plain declarativeNetRequest. The remaining thirteen do the job with scripting, webNavigation and webRequest.
That permission on its own settles nothing, and it is worth being precise about why. Chrome’s plain declarativeNetRequest permission, combined with host permissions, grants the same redirect capability. The two differ in how host access is granted, not in what they allow. The string is a useful marker for a particular pattern. Its absence does not establish that an extension cannot redirect, and its presence does not establish that one does.
What separates these two is not any single permission. It is the combination: that permission set, host access to every site, a content script running at document_start everywhere, thousands of standing redirect rules that arrive from a server rather than from the package, and a tp. tracking subdomain sitting alongside its parent domain on shared infrastructure.
Five of the sixteen do score on individual components: ShopBack, Cently, Coupert, LetyShops and Adblock for Youtube. In every case it is the same two points, host access to every site and a content script at document_start, which is ordinary equipment for a shopping extension. Coupert adds one more for referencing four merchants from the list.
None of them scores on either of the two components that actually separate these two extensions: a known infrastructure domain, and a tp. subdomain sitting alongside its parent. Those are worth five of Cashback Master’s nine.
Fourteen of the sixteen run their own infrastructure under their own brand. Cashback Assistant is Opera’s, and Cently shares a codebase and a backend with four antivirus-branded extensions. None of the sixteen carries the tp. signature. None of the sixteen matches the full pattern.
This is not what the category looks like. It is what these two look like.
Two Declarations Worth Reading
On Cashback Master’s own store page, under Privacy:
“The developer has disclosed that it will not collect or use your data.”
Chrome’s network log shows the extension POSTing to cbmaster.pro/update_user_settings, and fetching static.cbmaster.pro/avatar/…/get, which carries what appears to be a per-user identifier.
And under Details:
Non-trader. “This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.”
An extension with 100,000 users that earns affiliate commission on purchases has declared it is not trading. That declaration strips EU consumer protections from everyone who installs it.
What a Merchant Should Do About It
Test your own storefront, more than once. Clean browser profile, install the shopping extensions your customers plausibly have, type your own address, and watch what happens. That is the entire method used here, and it takes twenty minutes. Do it more than once, and from more than one connection, because as this piece shows, a clean result on a single attempt can mean nothing at all.
Use chrome://net-export, not just DevTools. Extension requests come from a service worker, not the page, so they never appear in the page’s Network tab. This is why the effect is visible, and the cause often isn’t.
Read the package, not the listing. What an extension is permitted to do is declared in its published package, and you can download and read that without installing anything. The tool I used for this article is public. One command per extension, and it prints the permissions, the content scripts and the hardcoded endpoints. A store listing describes what a product is for. The package describes what it is able to do, and the two are not always the same thing.
Remember the package is only half of it. Permissions are declared and reviewed. What an extension actually does with them can arrive afterwards, from a server, and change whenever that server decides. Reading the package tells you the ceiling, not the behavior.
Ask your networks what a partner’s traffic actually is. Not the category it’s filed under. What fires, when, and whether a user action was required.
Write extensions into your program terms. Most terms cover paid search and trademark bidding in detail and say nothing about browser extensions, sub-affiliate transparency, or stand-down rules. If your terms don’t address it, you haven’t permitted it or prohibited it. You haven’t decided.
And if you have either of these installed yourself, remove it. Not because cashback extensions are inherently bad, but because you cannot see what these two are doing, and their own store listings do not tell you.
Right of Reply
I wrote to both developers on 22 September, six days before publication, at the contact addresses on their store listings, setting out these findings and asking them to respond.
Neither has replied. If either responds after publication, I will add their response here in full and unedited.
I also wrote to RewardAny, which appeared in the redirect chain in my previous article. It replied before that piece went out, saying it has no relationship or affiliation with Cashback Ninja, and declined to discuss the member account the chain passed through, citing its privacy policy.
I went back to them afterwards with the exact inbound URL and the publisher ID it carries, so they could locate the traffic in their own records under whatever name they hold it. They have not replied.
I have not contacted Kiwi.com, Trainline, or the affiliate networks in these chains. They are the parties losing customers and paying commission, not the ones causing it.
Redirect chains captured from Chrome’s History database and chrome://net-export. Extension packages downloaded from Google’s own update endpoint and inspected without installation, using crx-fingerprint, which I have published under an MIT licence. Configuration and rule endpoints read from the extension’s own background script and queried directly on 29 September 2026. Initial context on browser extension monitoring provided by Marcode. The tests and findings above are my own.
Need Help Reviewing Affiliate Fraud and Leakage Risk?
Affiliate Manager Expert provides founder-led affiliate program management, audits, tracking reviews, compliance reviews, and program cleanup for SaaS, software, fintech, e-commerce, and digital product brands.
If you want to know what is actually firing inside your program, I can help you review where it is exposed: browser extensions, coupon leakage, partner overlap, sub-affiliate opacity, attribution rules, program terms, commission logic, and partner quality.
Book a free affiliate program review, and I’ll tell you what I find.
Quote of The Week
“There is nothing more deceptive than an obvious fact.” ― Sherlock Holmes, in Arthur Conan Doyle’s The Boscombe Valley Mystery (1891)
Leave a Reply
Want to join the discussion?Feel free to contribute!