Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Reactivation Violations by Wildfire Shopping Extensions

Дата публикации: 28-09-2026 20:38:49

Wildfire makes a variety of white-label cashback browser extensions. Some of their extensions—including at least Acorns, KashKick, and Super.com — open messages inviting user to “reactivate” cashback after another affiliate has claimed credit, even though affiliate network rules require the extensions to stand down in those circumstances. Here’s the sequence.  First, a user installs a … Continue reading "Reactivation Violations by Wildfire Shopping Extensions"

Основное содержимое страницы с новостью.

Wildfire makes a variety of white-label cashback browser extensions. Some of their extensions—including at least Acorns, KashKick, and Super.com — open messages inviting user to “reactivate” cashback after another affiliate has claimed credit, even though affiliate network rules require the extensions to stand down in those circumstances.

Here’s the sequence.  First, a user installs a Wildfire partner shopping extension.  When a user browses a merchant site, the extension pops open a window inviting the user to click and earn cashback.  Suppose the user later clicks an affiliate link from another publisher to the same merchant. Wildfire then pops open a “reactivate” window encouraging the user to click the Wildfire offer again—thereby replacing the other publisher’s attribution with Wildfire’s.

See also this WildFire Acorns video showing me browsing Zulily, receiving and clicking a Wildfire Acorns popup, then browsing Retailmenot, clicking back to Zulily, and receiving the Acorns “reactivate” popup.  All testing by me, on a test device, September 28, 2026 in my lab.

Network rules

Affiliate network rules disallow Wildfire’s “reactivate” window.  Consider the leading US affiliate networks

CJ’s Publisher Service Agreement prohibits software publishers from “usurp[ing] a Transaction that might otherwise result in a Payout to another Publisher.”  Wildfire’s reactivate window claims funds that “might otherwise” flow to another publisher.

Impact’s Stand-Down Policy requires publishers to “refrain from actions that could … interfere with existing publisher-referred traffic.”  Impact continues: “Upon detecting prior publisher attribution, software must suppress marketing prompts: Do not display pop-ups, banners, or notifications encouraging users to activate cashback or other affiliate offers.”  Wildfire’s reactivate window “encourag[es]” a user to activate cashback.

Rakuten’s Network Policies explain that “’Stand-down’ means the software may not activate or redirect the end user to the advertiser site with their Supplier Affiliate link for the duration of the browser session.”  Wildfire’s reactivate window is a form of extension “activat[ion]” prohibited by that sentence.

Wildfire’s role

Because Wildfire supplies the underlying technology for multiple white-label extensions, the same design can affect multiple publishers and merchants. My technical analysis, below, indicates that the stand-down/reactivation functionality resides in Wildfire’s shared code rather than being separately implemented by each white-label extension.

Implementation details

Reviewing Wildfire’s code within the Acorns extension, I found that the reactivate function has a featureFlag setting. From src/shared/config.js:

featureFlags: { lostAffiliationDetectionEnabled: true }

I also reviewed the Wildfire code that consumes this setting and decides how to proceed.  First, handleAffiliateStandDown.js watches web requests.  If a request’s query string contains a parameter from the LostAttribution list in _standDownPolicy, it sets potentialLossOfAttributionDetectedFromTab. Later, handleLostAttribution.js runs when the tab finishes loading.  It checks that cashback was already activated for that domain and that the URL differs from the original activation URL.  It then sends a LOST_ATTRIBUTION message to the tab, prompting the reactivate message as shown above.

The code indicates that the lost-attribution/reactivation feature resides in Wildfire’s shared code, rather than being separately implemented by the individual shopping extensions. That is consistent with remarks on Wildfire’s site (“white-label”).

Remediation

In the telemetry sent from the user’s device to Wildfire’s server, Wildfire tracks the fact that another affiliate’s link was clicked (“LOST_AFF” in yellow below), but also the specific other affiliate that was to be credited (usually visible in the merchant’s landing page, url= parameter, in green below — here RetailMeNot with Rakuten publisher ID OOTtr9mlaCk).

GET https://wild.link/_sales/offer-view?d=51138069&c=4782751
&sc=&tc=696f885f-40ef-4cc1-aacb-357784ef9a6b&session_id=
b41104b1-8a3a-4b2f-abb4-03941e3c255f&session_step=1
&url=https%3A%2F%2Fwww.zulily.com%2F%3Futm_source%3DAffiliate
%26utm_medium%3Daffiliate%26utm_content%3DRetailMeNot
%26ranMID%3D54167%26ranEAID%3DOOTtr9mlaCk%26ranSiteID%3D
OOTtr9mlaCk-CHIdllrXwa1nTnnT5TSbWw&view=LOST_AFF
&action=OFFER_VIEWED&app_version=11.11.1 HTTP/1.1

This data creates a path to return funds to the publishers who would have been paid had it not been for Wildfire’s reactivate messages.  Any payment Wildfire and its partners received in a LOST_AFF session could then be identified for review and, where appropriate, redirected or reimbursed to the affected affiliate (per the green url= parameter).

Full remediation would also require Wildfire paying networks’ costs of investigating the violation.

“Activate & Close” with less prominent “Dismiss”

(added October 2, 2026)

The second and third screenshots, above, show unusual text in the top-right corner of the Wildfire popups: “Activate & Close.”  But the top-right of a popup is where users reasonably expect an X button that closes the window and takes no other action.

By placing “Activate & Close” in the top-right, and treating a click there as supposed basis to invoke an affiliate link, Wildfire popups invoke affiliate links in circumstances where users are best understood not to have requested that Wildfire do so.

An astute user will find a “Dismiss” link in the bottom-center of the Wildfire windows.  But that’s not a normal place for a button to close a window.

Testing other Wildfire extensions, I also see Acorns and Kudos using the misleading “Activate & Close” (at top-right) and “Dismiss” (at bottom-center) on their principal mobile screens to present affiliate links (though Acorns does not do this in its reactivate message, first screenshot above).  Acorns screenshot below (from video at 0:01).

Google’s Chrome Web Store allows affiliate links only when there is a “direct and transparent user benefit.”  But Wildfire button labels and placement are not “transparent” when the close function is moved to bottom-center, and when the top-right link serves both to close Wildfire’s popup and to invoke an affiliate link.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1More Phia Affiliate Misconduct: On-Exit Clicks and Cookie Refreshes012.4911-08-2026
2Forced Clicks and Stand-Down Violations by Shopping Plugin Phia014.0609-07-2026
3Code of Conduct for Affiliate Marketing Software018.8707-04-2026
4Why McDonald’s, Dunkin’, Starbucks, and other chains keep making their rewards programs worse—and getting away with it08.0630-09-2026
5The Best Rewards Apps of 2026 to Turn Your Free Time Into Real Money013.2508-10-2026
6Agentizing Privacy Preferences without Privatizing Data Protection Policy07.7204-06-2026
7Аферисты начали распространять вирусные файлы, обещая бонусы на заправку014.3928-09-2026
8Расширение браузера может тайно взломать запросы к нейросети09.1829-09-2026
9МВД: Мошенники распространяют вирусы под видом бонусов на заправку08.3628-09-2026
10Киберэксперт: расширение браузера может добавить скрытую инструкцию для ИИ07.5929-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 14.62. Источник: www.benedelman.org.