31 Security and Privacy Brands Are on a Browser Extension’s Redirect List. None of Them Can See It. (#25)

October 5, 2026

Browser extension redirect investigation showing 31 security brands on a hidden redirect list, with affiliate traffic passing through multiple intermediaries.

TL;DR

Cashback Master is a Chrome extension with 100,000 users that holds standing instructions to rewrite navigations to thousands of merchant domains. I published the list it was handing out on 29 September: 4,295 domains.

I checked the list against 63 security and privacy brands. Thirty-one are on it. Twelve antivirus companies, twelve VPNs, four password managers, and three storage and identity services.

Among them are Norton, Avast, AVG and Avira, all four of which publish shopping extensions of their own.

The list is not static. Between 24 and 29 September, 704 domains dropped off and 562 were added. Surfshark went from absent to one of the fourteen brands the extension advertises to users, at 45%, inside five days.

And not one of those companies is in a position to know. What reaches their affiliate program belongs to a chain of intermediaries, three of which have no working contact address at all.

What I Checked

In the last piece, I showed how this extension works. The redirect rules are not in the package Google reviewed. They arrive from the extension’s own server after installation, are registered as session rules that Chrome discards when the browser closes, and are rebuilt the next time it starts.

That piece was about one merchant. This one is about who else is on the list, and why, almost certainly, none of them has the first idea.

The capture is dated 29 September 2026, and the full list is published, so every count below can be checked by searching it.

Antivirus and security suites: 12 of 16

Norton, McAfee, Avast, AVG, Avira, Bitdefender, Malwarebytes, F-Secure, Sophos, Webroot, 360 Total Security, Intego.

Not on it: Kaspersky, ESET, Trend Micro, Panda.

VPNs: 12 of 17

NordVPN, ExpressVPN, ProtonVPN, Surfshark, IPVanish, Hotspot Shield, PureVPN, Private Internet Access, TunnelBear, FastestVPN, Ivacy, hide.me.

Not on it: CyberGhost, Windscribe, Mullvad, Atlas, StrongVPN.

Password managers: 4 of 12

LastPass, 1Password, Keeper, NordPass.

Not on it: Bitwarden, KeePass, Dashlane, RoboForm, Enpass, Proton Pass, Sticky Password, Passwarden.

Secure storage, identity and data removal: 3 of 18

IDrive, Internxt, BeenVerified.

The Boring Explanation Is Probably The Right One

Before the interesting part, the unglamorous reading, because it’s almost certainly correct.

This is not a list of security products. It is a list of companies that run affiliate programs.

Look at who’s missing. Bitwarden and KeePass are free and open source. Mullvad takes cash in an envelope and runs no referral scheme. Proton Pass, Tuta and Tails are absent for the same reason: there’s no commission to claim.

Nothing here suggests the extension singles out security software. These thirty-one are thirty-one rows out of 4,295, sitting alongside 1800flowers, Crocs, and a long tail of gambling sites. The list tracks money, not category.

I’m also not claiming anything about credentials. This extension redirects navigations. Nothing I found shows it reading anything out of a password vault, and I wouldn’t print it if I hadn’t tested it.

The List Is Being Managed

The more useful finding is that it moves.

I captured the list on 24 September and again on 29 September. In five days, 704 domains dropped off and 562 were added, taking the list from 4,437 domains to 4,295. That’s more than a quarter of it changing in under a week.

The security brands moved with it. Surfshark, Private Internet Access, TunnelBear and Sophos were added. CyberGhost came off.

Surfshark is the one worth sitting with. On 24 September it wasn’t on the list at all. On 29 September it wasn’t only on the list but one of the fourteen brands the extension displays to its users, advertised at 45%. A VPN company went from absent to the shop window in five days.

So a merchant who checks this once and finds nothing has learned what the server said that day. Nothing more.

Four Companies On Both Sides Of It

Norton, Avast, AVG and Avira are all on the list.

All four also publish shopping extensions of their own: Norton Shopping Assistant, Avast SafePrice, AVG SafePrice, Avira Safe Shopping. They activate on merchant domains and monetize close to the point of conversion. I wrote about that category in an earlier piece.

So the same four brands appear as merchants whose traffic another extension is set up to intercept, and as publishers of extensions doing broadly similar work on other people’s traffic.

In February 2024, the FTC ordered Avast to pay $16.5 million and barred it from selling browsing data for advertising purposes, over conduct in which its browser extensions and antivirus software collected users’ browsing histories and a subsidiary sold them.

I’m not suggesting any of these four is doing anything improper in any program today. The point is narrower and harder to answer: most merchants running these partners never made a decision about them. Nobody evaluated the partner, weighed the brand risk, or concluded the behavior was acceptable. The partner arrived through a subnetwork, and the reporting never surfaced it as an extension.

Why None Of Them Can See It

This is the part that explains everything above.

When I typed a train company’s address with Cashback Ninja installed, the navigation went through six intermediaries before it reached the merchant. When I typed a travel site’s address with Cashback Master installed, it went through three and never arrived at all.

For this piece, Marcode ran those intermediaries against their own extension monitoring data, which covers tens of browser extensions over the last six months. The result divides cleanly in two.

Exclusive to these two extensions: n-tab.pro, showmelinks.com, and the chinesean.com parameter wId=67376. None of the three appears behind any other extension they monitor.

Shared with many others: pickalink.com appears behind 24 extensions. The RewardAny member account userId=10460, which my own visit was credited to, appears behind 14.

That’s a supply chain, not a disguise. These two extensions run their own front end and their own first hop, then hand off to monetization services that serve a lot of other people. And every rung down, the traffic looks more ordinary. By the time it reaches the affiliate network, what arrives is a publisher ID belonging to a platform with a marketing site and 40,000 merchants.

I checked whether the intermediaries sit on the same infrastructure as the extensions. They don’t. Different hosts, different providers, no shared signature. Separate businesses, stacked.

Three Of Them Have No Door

On 29 September I wrote to all four intermediaries, offering a right of reply.

pickalink.com     delivered
n-tab.pro         bounced
showmelinks.com   bounced, all five addresses
monetoad.com      bounced, all five addresses

PickaLink runs Google Workspace and received it. The other three publish no MX record at all, which anyone can check:

nslookup -type=mx showmelinks.com

n-tab.pro is the sharpest of them. It prints [email protected] on its own homepage. That address bounces.

So the layer sitting between a browser extension and a merchant’s affiliate program, taking a cut on the way past, is in three cases out of four not contactable. There is no published route to reach them, by me, by a merchant, or by a network trying to trace a click.

The Same Layer Turns Up Elsewhere

One of those intermediaries has a history worth noting.

Marcode’s data shows monetoad.com appearing in paid search hijacking chains between November 2023 and May 2024, under four advertiser accounts unrelated to these extensions, in a different URL format, well before anyone was tracking extensions. In those chains, it sat at the end: the last hop before the user reached the merchant, which is where affiliate tracking is applied.

The parties running those ads were doing the hijacking. Monetoad was the layer they monetized through. I’m not naming them, because that’s a separate matter I haven’t independently verified, and they haven’t had an opportunity to respond.

The relevant point is structural. The monetization layer is reusable. The same rung that carries a browser extension’s rewritten navigation today carried somebody else’s paid search hijacking two years ago, and the merchant at the end of it saw a publisher ID either way.

What I Am Not Claiming

Being on the list isn’t an accusation. It means the extension held an instruction to redirect navigations to that domain on the day it was captured. The merchant is the party on the receiving end and, in most cases, has no idea the rule exists.

A rule isn’t a transaction. I have shown the instructions exist and that they fire. I haven’t audited anyone’s program, and I’m not claiming any specific commission was paid to anyone.

Thirty-one of sixty-three is not a rate. I chose which brands to check. A different list gives a different fraction, and the denominator is mine.

A clean result can mean nothing. Whether this extension arrives with its rules loaded is decided by its server, per request, after installation, and the answer changes. I have seen it arrive inert on one install and fully loaded thirteen minutes later. A zero-rule result tells you what the server said that time.

The intermediaries are not accused of anything. PickaLink’s own publisher terms prohibit “forced clicks” and state that a publisher won’t employ “toolbars or toolbar applications that offer no value to End Users”. On the evidence, pubId=10592 looks like an account operating outside those terms, and PickaLink looks like one more party whose system is being used.

One identifier is absent from a dataset, not from the world. wId=67376 appears only in these chains in Marcode’s data. They do not ingest merchant-side affiliate data from chinesean.com, so that is absence from their view rather than confirmation of what a merchant would see in their own reporting.

Check Your Own Domain

The full list is published here, searchable, with the capture date on it. There’s nothing to sign up for.

If your domain is on it, that’s a starting point rather than a finding. The next question is whether anything in your affiliate reporting corresponds to traffic that arrived this way, and that can only be answered from your own data.

What A Merchant Should Do About It

Check more than once. The answer comes from a server after installation, and it changes. A quarter of this list turned over in five days.

Ask your network for the click path, not the partner name. Which publisher, which sub-publisher, and whether a user action was required. If you run a program on chinesean.com, wId=67376 is an account identifier you can hand them today.

Ask who your sub-network’s publishers actually are. A sub-affiliate network holds the relationship on your behalf for many publishers at once. That is a legitimate and useful structure. It also means the only party positioned to see what feeds it is the one earning on the volume.

Write extensions into your program terms. Most terms cover paid search and trademark bidding in detail and say nothing about browser extensions, sub-affiliate transparency, or stand-down rules when another partner is already present. If your terms don’t address it, you haven’t permitted it or prohibited it. You haven’t decided.

And if you sell security or privacy, decide deliberately. You may conclude that shopping extensions are a legitimate partner category and that you’re happy to pay them. That’s a defensible position. What’s not defensible is finding out from a stranger’s article which ones are in your program.


Domain list captured 29 September 2026 from Cashback Master’s own server and published in full. Extension monitoring data provided by Marcode. I wrote to PickaLink on 29 September and gave them until 6 October; at the time of publication, they had not responded, and I will add anything they send in full. Messages to the other three intermediaries did not deliver. Disclosure: Marcode and I have agreed a referral arrangement under which they pay me a fee on clients I introduce to them. They had no editorial input in this piece, and the domain list and testing here are my own.

Need Help Reviewing Affiliate Fraud and Leakage Risk?

Affiliate Manager Expert provides founder-led affiliate program management, audits, tracking reviews, compliance reviews, and program cleanup for SaaS, software, fintech, e-commerce, and digital product brands.

If you want to know what’s actually firing inside your program, I can help you review where it’s exposed: browser extensions, coupon leakage, partner overlap, sub-affiliate opacity, attribution rules, program terms, commission logic, and partner quality.

Book a free affiliate program review, and I’ll tell you what I find.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Quote of The Week

“The purpose of a system is what it does.” ― Stafford Beer, cybernetician, 2002