Affiliate Fraud Tools

Three free checks for affiliate link hijacking, the quiet kind where a browser extension redirects your traffic and someone else earns the commission. Nothing to sign up for, nothing to install, and every result is reproducible from your own machine.

Is your domain on a browser extension’s redirect list?

Cashback Master is a Chrome extension with 100,000 users. It holds standing instructions to rewrite navigations to thousands of merchant domains, so that someone typing a merchant’s address arrives carrying affiliate tracking instead. The list below is the one its own server handed out on 29 September 2026.

  • 4,295domains on the list
  • 14advertised with a name and a rate
  • 704dropped since 24 September
  • 562added since 24 September

Partial matches work. Try kiwi, norton, or your own brand.

Captured 29 September 2026 from a United States connection, read from cbmaster.pro directly rather than from a browser. Download the full list as a plain text file.

The fourteen it advertises

The extension shows users a short list of brands with cashback rates. Everything else on the list is acted on without being displayed anywhere.
Domain Shown to users as Advertised rate
airalo.com Airalo 13.5%
coohom.com Coohom 21%
fanatics.com Fanatics 4.2%
gamivo.com Gamivo 3.5%
hover.com Hover 15%
kiwi.com Kiwi.com 3%
onetravel.com Onetravel up to 15%
strawberrynet.com StrawberryNET up to 9%
surfshark.com Surfshark 45%
tidio.com Tidio 23%
trip.com Trip.com up to 3%
tvcmall.com TVCMall up to 9.1%
voghion.com Voghion up to 9.5%
wowangel.com WOWANGEL up to 6%

What a result does and does not mean

A match is not an accusation. It means the extension held an instruction to redirect navigations to that domain on the day it was captured. The merchant is the party on the receiving end and in most cases has no idea the rule exists.

No match does not mean you are clear. This is one snapshot of one extension. Between 24 September and 29 September 2026, 704 domains came off this list and 562 went on. That is roughly one entry in six turning over in five days. Whatever the list said on the days your programme was taking traffic is not what it says now, and nothing in your affiliate reporting would show you the difference.

Read an extension’s package without installing it

crx-fingerprint downloads a Chrome extension from Google’s own update endpoint and prints its permissions, its content scripts and every external host hardcoded in its code. It never installs anything and never runs the extension’s code.

python crx-fingerprint.py <extension-id>

One Python file, no dependencies, MIT licence. The extension ID is the 32-character string at the end of any Chrome Web Store URL.

One limitation worth knowing. Reading the package tells you the ceiling, not the behaviour. Cashback Master’s package contains no redirect rules at all. They arrive from its own server after installation, which is why the list above had to be captured rather than read out of the code.

Test your own storefront in twenty minutes

  • Make a clean browser profile

    New Chrome profile, not signed in to anything, nothing else installed.

  • Install one extension

    One at a time, or you cannot attribute what you see to any of them.

  • Start Chrome’s packet logger

    Go to chrome://net-export. Not DevTools. Extension requests come from a service worker rather than the page, so they never appear in a page’s Network tab.

  • Type your own address

    Into the address bar, then press Enter. Do not click a link. Do not use a bookmark.

  • Watch the address bar, then read the log

    You are looking for requests your own domain never received, and for an initiator field naming an extension.

  • Run it again with the extension disabled

    Without that control you have an anecdote. With it you have a result.

Do it more than once, and from more than one connection. These extensions decide what to do per request, on a server. A clean result on a single attempt can mean nothing at all.

Where these came from

These came out of an investigation into browser extensions that rewrite typed navigations to insert affiliate tracking. The method, the evidence and what I am not claiming are set out in full in both pieces:

If you would rather someone did this properly

A lookup tells you whether one extension held a rule for your domain on one day. It cannot tell you whether anything in your programme was actually credited for traffic that arrived this way. That question has to be answered from your own transaction data.

Or read how an affiliate fraud audit works.