How it works and how our new extension aims to prevent it!
Imagine this scenario: You’re watching a tech review video, click an affiliate link in the description, and purchase a product. The creator earns a 5% commission. That is standard, honest affiliate marketing.
Now imagine a completely different scenario. You never clicked a creator’s link, nor do you even know who they are. You are simply browsing online when a hidden background script quietly drops an affiliate tracking cookie into your browser storage. Days later, you purchase something from that retailer, and an unknown third party receives a payout for a sale they had no hand in driving.
This is not a theoretical glitch; it is cookie stuffing. It is an attribution exploit running silently across the web, turning legitimate referral systems into an accounting nightmare. In this post, we break down how cookie stuffing works, why major companies and browser extensions have faced federal litigation over it, and what you can do to protect your browser.
What Exactly Is Cookie Stuffing?
To understand cookie stuffing, you must understand last-click attribution. Most e-commerce affiliate programs operate under a simple rule: whichever affiliate tracking cookie was placed most recently in a user's browser receives 100% of the commission when the user checks out.
The merchant's server assumes that the presence of an affiliate cookie indicates a real referral. However, the server cannot distinguish between a user deliberately clicking an affiliate link and a rogue script forcibly setting that cookie in the background.
In a normal transaction, a user clicks an affiliate link, arrives at the store, receives a tracking cookie, and completes a purchase. In a cookie-stuffed transaction, the user visits a site or runs a browser extension that silently makes background requests to an affiliate tracking URL. No new tabs open, no prompts appear, and no user action is required. Yet, any existing creator cookie is overwritten, and the attacker claims unearned credit for the eventual purchase.
The attacker isn't stealing credit card numbers or account credentials—they are stealing financial attribution.
Checkout this graphic for a further explanation of how cookie stuffing differs from a regular cookie exchange on the web.

Why Attribution Fraud Harms Everyone
While consumers pay the same retail price regardless of who gets credited, cookie stuffing breaks the financial ecosystem of the web:
- Legitimate Creators: Reviewers and creators invest heavily in producing content to earn referral income. Cookie stuffing overwriting their cookies effectively robs them of their primary revenue stream.
- Retailers & Merchants: Brands pay billions in affiliate marketing to acquire new customers. Cookie stuffing forces merchants to pay commission fees on organic sales that were already taking place.
- Consumers: Browsers are forced to execute unauthorized background requests, consuming network bandwidth and exposing users to hidden tracking without consent.
Technical Mechanics: How Cookies Get Stuffed
Mechanically, cookie stuffing forces a browser to load an affiliate tracking URL without conscious user interaction. Historically, bad actors relied on primitive web hacks:
- Hidden iFrames: Loading invisible 1x1 pixel windows at the bottom of a webpage that loaded dozens of affiliate links simultaneously.
- Invisible Image Tags: Embedding HTML
<img>tags where the source pointed to an affiliate redirect endpoint rather than an image file. - Background Redirects: Bouncing HTTP requests through multiple tracking links before landing on the target destination.
When a browser makes a request to any web server, the server can return an HTTP header containing Set-Cookie. The browser automatically stores this cookie without requiring user prompts. The moment the tracking URL is requested, the affiliate receipt is stamped.
While modern browser security policies mitigated many of these older tricks, a far more powerful vector emerged: browser extensions.
The Modern Vector: Browser Extensions
Browser extensions operate with elevated permissions inside the browser environment. Many extensions request permission to "read and change all your data on all websites". This access allows them to monitor visited URLs, modify DOM elements, intercept network traffic, and execute background scripts.
While these permissions are necessary for legitimate tools like coupon finders or ad blockers, they also provide an ideal mechanism for attribution manipulation. An extension can quietly monitor when you visit a shopping site and inject an affiliate cookie right before you check out.
A History of Federal Prosecutions
Cookie stuffing is not a recent phenomenon. Federal law enforcement has prosecuted affiliate fraud as wire fraud for decades.
In a landmark case, the U.S. Department of Justice prosecuted Brian Dunning, one of eBay’s top affiliate marketers. Federal prosecutors proved that between $200,000 and $400,000 of his company's $5.2 million in eBay affiliate payouts were generated through fraudulent cookie stuffing via hidden pop-unders and tracking scripts. Dunning was sentenced to 15 months in federal prison.
In another case, developer Christopher Kennedy pleaded guilty to wire fraud after creating and selling "Saucekit"—software specifically engineered to automate cookie stuffing. These cases established clear legal precedents: cookie stuffing is federal wire fraud.
High-Profile Controversies: PayPal Honey, The Quartering, & Capital One
In recent years, attribution practices have sparked intense public debate and litigation across major consumer tools. It was the original MegaLag video about Honey where I learned about the seedy underworld of Affiliate Link stealing, see that video here: Exposing the Honey Influencer Scam . After that video, I personally did not hear much else regarding the topic. I did start paying attention a bit more to people putting their affiliate link in their video description, and once you start looking for it, you realize they are EVERYWHERE! So many of my favorite YouTubers are using this to support themselves. Which is why I really find the whole thing just awful. Imagine your favorite "busker", that street musician who is out there performing amazing covers for basically nothing. Now imagine a well dressed man pulls up in a BMW Z Roadster, top down, hops out, 3 piece pinstriped suit, 10 bands on the wrist, and walks over to the musician. You think hes going to tip the guy, when instead he does the old "look over there", points left, grabs the dudes tip cup, hops back in his car, and drives off. Essentially, when Paypal is out there stealing from YouTubers, thats exactly what is happening. Whats next? Using the power of their corporation to steal a serving from meat off of Gramgrams tray at the home? Literal corpo sponsored candy from baby theft?
There is something truly awful when you have the full weight and backing of a multi billion dollar organization facilitating the theft of assets from individual artists. As if it could not get worse, we now have worlds richest chlamydia haver's daughter ALSO setting up institutional theft from the creator economy.
Now we are going to go deep on some of the biggest, most high profile examples of cookie stuffing that have occurred recently.
The Phia Startup Scandal
Cookie stuffing resurfaced in major tech headlines in mid-2026 when reports emerged surrounding Phia, a shopping platform co-founded by Phoebe Gates and Sophia Kianni.
Investigative reports alleged that Phia's software automatically placed and refreshed affiliate tracking codes for thousands of partner brands, allowing the platform to claim credit for sales it did not generate. Subsequent reporting alleged that founders were aware of the background attribution mechanics months before disabling the feature. Independent analysts noted that forced clicks and automated cookie dropping accounted for a significant portion of the platform's merchandise volume before being shut down.
Checkout these two TechCrunch articles for the whole scoop:
MegaLag VS Honey
As mentioned earlier, handsome YouTuber and man with buttery smooth voice, MegaLag published this DAMNING expo on Paypal offshoot "honey". Exposing the Honey Influencer Scam. This really put him on the map, and he deserved it. The video actually brought about real change, and basically put Honey🍯 in the ground. If you havent been keeping up with the scandal, he actually released an update to it just recently, and that video is also a banger. It really shows just how scummy Honey was, how they tried to hide it, basically refused to apologize, and got dumped by everyone over their bad business practices. Honey Gets Terminated as Lawsuits Proceed
Luther Morgan VS TheQuartering
Saving the best for last, this case is one near and dear to my heart. Ole Jer was really being a sneaky dick with this one, "allegedly". In another one of his amazing expose videos, Luther uncovered that Jer was basically running the same scam honey was, just on a much smaller scale. America's Least Wanted Coffee Part 2: The Truth About the CoffeeBrandCoffee Affiliate Program!
This was the video that really got me thinking about this problem, on a coding level. While its fun to laugh at corpos getting caught doing people dirty, the though that I might be getting tricked into helping someone I hate get a leg up in life, at the expense of people I actually do like, well that really pissed me off. This is where the initial idea of "Cookie Sleuth" started to take shape. Shout out to Don and Channel 404 News who also broke this story as well.
Capital One
A coalition of creators filed a class-action lawsuit alleging that Capital One's browser extension diverted affiliate commissions away from referring creators. Capital One denied wrongdoing and settled the suit out of court, illustrating how widespread attribution disputes have become.
The Detection Problem: Why You Can't See It
The primary challenge of cookie stuffing is its invisibility. Everyday web users do not monitor Chrome Developer Tools, inspect HTTP redirect chains, or audit Set-Cookie header parameters while shopping online.
Because users cannot spot background network requests manually, protecting your browser requires active real-time monitoring of browser storage behavior.
Becoming a bigger problem
As this article has shown, Cookie Stuffing isnt anything new, and if you look into the sources listed, you can pull out some interesting stats showing that this problem is only going to get worse.
Every cookie that gets stuff is potentially another creator that is no longer able to make the content they love, through no fault of their own. This isnt them saying or doing the wrong thing, its often corporations with more money than sense, stealing from them directly. If that doesnt get your blood boiling then you might want to see a doctor because you're likely catatonic.
Take Control with Cookie Sleuth
To solve this transparency gap, Cookie Sleuth is being created. It is an open-source tool designed to bring complete visibility to your browser storage, cookies, and intentional + automatic affiliate linkage.
Cookie Sleuth monitors incoming cookie modifications in real time. Whenever a background script or extension attempts to silently inject or overwrite affiliate tracking parameters, Cookie Sleuth flags the event, records a timestamp, captures the offending domain, and presents the evidence in a clean dashboard.
- GitHub Repository: Inspect the code and contribute on the Cookie Sleuth Repository.
- Technical Threat Model: Read our comprehensive breakdown of attack vectors in the Cookie Sleuth Threat Documentation.
- Interactive Testing: Test your browser's vulnerability to cookie manipulation live at the Cookie Sleuth Testing Lab.
Cookies were created to maintain login sessions and remember user preferences. When third parties exploit browser storage to hijack financial attribution, visibility is your best defense.
Without getting to deep into the woods, I'll give a high level overview of the way it works. The repo is linked and open source, so anyone can download this and expand on it / see how it works.
To start with we have known markers and networks that we monitor
This is where I could really use the internet's help. Compiling this list is hard, and im sure there are a whole bunch of affiliate networks I'm missing. So if you see where I am coming up short, and know a what else should be included, please let me know.
const AFFILIATE_COOKIE_MARKERS = [
// High confidence to low confidence
{ pattern: /aff_id|affid|affiliateid|affiliate_id/i, score: 10, label: 'Affiliate ID' },
{ pattern: /clickid|click_id|cj_data|cjclick|irclickid/i, score: 10, label: 'Click tracking ID' },
{ pattern: /subid|sub_id|sid|transaction_id|txid/i, score: 9, label: 'Sub-ID / Transaction ID' },
{ pattern: /partnerid|partner_id|pid/i, score: 8, label: 'Partner ID' },
]
const KNOWN_AFFILIATE_NETWORKS = [
// Major networks
{ pattern: /anrdoezrs.net|dpbolvw.net|qksrv.net|cj.com|commission-junction/i, name: 'Commission Junction (CJ)' },
{ pattern: /impact.com|impactradius.com|pxf.io|ojrq.net/i, name: 'Impact' },
{ pattern: /shareasale.com|shareasale-analytics.com/i, name: 'ShareASale' },
{ pattern: /awin1.com|awin.com|zenaps.com|dwin1.com/i, name: 'Awin' },
]
Evaluate the threats
Once a match is found, we start seeing how that cookie got into the browser, and whether or not it was legit.
const evaluateCookieThreat = (
cookieName: string,
cookieDomain: string,
requestUrl: string,
deliveryMechanism: string,
tabId?: number,
tabUrl?: string,
statusCode?: number
) => {
let score = 0;
const reasons: string[] = [];
...
Display the results
Anytime a possible stuff / scam is detected, the icon changes color and flashes a ! look at me sign. When you open up the extension, it shows you what, when, and why it might be a scam. From there you can get more info about the type of stuff that occurred. This is another area where the extension needs some work. The code right now makes an educated guess, and provides how confident it is, and if its confident enough (like a blatant stuff), it would be nice if there was some kind of Call to Action where you could report the abuse to whomever is being screwed out of their money. Let me know in the comments or drop me a message with what you think should be happening if a positive detection is found should be.
Also, follow me to stay up to date, as very soon the Cookie Sleuth extension is going to get submitted for approval in the Google Chrome Extension Marketplace. Seeing as I already have a game published in the Android Store. I am hopeful getting into the Chrome store wont be much of a hassle. Wish me luck!
References
- Track360 Glossary: Cookie Stuffing
- U.S. DOJ Cybercrime Press Release (Kennedy Case)
- The Verge: Google Restricts Chrome Extension Affiliate Injection
- Business Insider: Creators Sue PayPal Over Honey Extension
- Federal Court Filing: Creator vs. PayPal/Honey
- TechCrunch: Phia Accused of Cookie Stuffing (July 2026)
- TechCrunch: Phia Founders Reportedly Knew of Behavior (Aug 2026)
- People Magazine: Phia Responds to Accusations
- Justia: eBay Affiliate Litigation Case Filings
- LeeStack: Attribution Systems Are Security Systems
- arXiv: Malicious Browser Extension Research








Comments
Add Comment
All Comments
// NO_COMMENTS_IN_BUFFER
Establish initialization protocol by creating the baseline entry trace.
System Moderation Interceptor is ON for this communication hub. All user transmission vectors must clear access protocol filtration approvals before broadcasting logs live to public network arrays.