SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
Description
The SelectorsHub Chrome extension, used by approximately 400,000 users, has been found to open advertisement tabs selected by its server without any user interaction. The extension fetches ads from a server that can change the URLs dynamically without extension updates. It also collects cookies broadly and sends user selectors to a domain that currently redirects to a gambling site. This behavior resembles adware and poses privacy and security concerns, especially for users in sensitive environments.
Reddit Discussion
I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything.
Every couple of days the side panel pops up a "community link" and says "100% Safe, No Spam, No Malware." Five seconds later the tab opens by itself. The URL isn't in the extension. Their server picks it, and while I was analysing the extension the links changed three times with no extension update.
On install and update it skips the popup and just opens whatever the server sends.
The store page says they collect no data. The code still pings them daily, and the extension reads all your cookies to find one of its own instead of just fetching its own cookie value.
Another weird finding: there's a hidden Fix Selector button that sends the selector to shubads[.]testcasehub.net. VirusTotal - Domain - shubads.testcasehub.net
That host now redirects to a gambling site, blomehairdryers[.]com.
Nothing gets run today because the reply is HTML, but that's the server the eval path trusts.
Looks like adware, not password theft. I wouldn't leave it on a work browser, especially since this is a tool used by devs and tech people browsing protected endpoints in a company.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SelectorsHub, a Chrome extension with around 400k users, opens server-selected advertisement tabs in the background without user clicks. The URLs for these ads are not embedded in the extension but are dynamically provided by the extension's server, which can change them without updates to the extension itself. The extension also collects cookies broadly and sends user data to a domain (shubads.testcasehub.net) that now redirects to a gambling site. The extension's behavior includes opening tabs on install and update without user interaction and displaying a side panel with community links. This activity is consistent with adware rather than credential theft. The extension is used by developers and technical users, raising concerns about exposure in secure environments.
Potential Impact
The extension's unsolicited opening of advertisement tabs can lead to privacy violations by tracking user activity and cookies. The dynamic nature of the ad URLs and the redirection of the server domain to a gambling site increase the risk of exposure to malicious or unwanted content. While no direct credential theft or malware execution is currently observed, the behavior can disrupt user workflows and potentially expose users to harmful web content. The extension's broad cookie access and data transmission to an external server also raise privacy and security concerns.
Defensive Guidance
There is no official patch or vendor advisory available for this issue. Users, especially those in sensitive or corporate environments, should consider uninstalling the SelectorsHub extension to avoid unsolicited ad tab openings and potential privacy risks. Monitor for any updates from the extension developer or official sources for remediation. Avoid using this extension on work or security-sensitive browsers until the issue is resolved.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ac4108e2cdf04f6563a3738
Added to database: 10/05/2026, 21:03:10 UTC
Last enriched: 10/05/2026, 21:03:14 UTC
Last updated: 10/05/2026, 21:03:14 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.