All Vendors
advertising

Propellerads

Propellerads is an advertising vendor with a VRS of 80, flagged for 4 BTI codes including consent bypass (C09) and fingerprinting (C10). The ad network deploys visitor tracking and behavioral profiling across publisher inventory, creating moderate signal corruption (25), significant cost attribution exposure (65), and substantial legal tail risk (85).

89 IOCs1 detections100% pre-consent1 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Propellerads discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

1 detection across 1 site100% pre-consent activity
CRITICAL

Pre-Consent Activity

Propellerads was observed loading and executing before user consent was obtained on 100% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Publishers and advertisers face three core risks: (1) Audience attribution becomes distorted by cross-site profiling that misclassifies visitor intent, making yield optimization decisions unreliable. (2) Visitor behavior data flows across Propellerads network, exposing audience composition and content strategy to vendor analytics and potentially other network participants. (3) Legal exposure from consent bypass creates GDPR/CCPA liability that compliance teams cannot mitigate while maintaining ad network monetization.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Propellerads

  • Require data processing addendum with explicit cross-site tracking disclosure
  • Demand consent framework integration that blocks tracking until user acceptance
  • Implement audience data minimization to limit behavioral profiling scope
  • Configure ad delivery to prioritize contextual over behavioral targeting
  • Establish retention limits for visitor profiles and device fingerprints

If You're Evaluating Propellerads

  • Test consent mechanism to verify tracking respects publisher consent state
  • Verify geographic data processing boundaries for GDPR compliance
  • Review fingerprinting techniques and cross-site tracking mechanisms
  • Assess data sharing across network participants and third-party enrichment
  • Request disclosure of secondary audience data use for vendor intelligence

Negotiation Leverage

  • Propellerads deploys consent bypass and cross-site tracking across publisher network—demand contractual liability protection for GDPR/CCPA violations and explicit DPA terms
  • Visitor behavioral data flows across network creating shared audience intelligence—negotiate limits on cross-site profiling and data sharing with other publishers
  • Device fingerprinting enables persistent tracking across publisher properties—require transparency into fingerprinting techniques and user deletion capabilities
  • Cross-site attribution may distort audience quality assessment and yield optimization—establish baseline measurement methodology for ad performance
  • Legal tail risk of 85% reflects network tracking architecture—evaluate whether monetization value justifies regulatory exposure or consider privacy-respecting ad networks
Runtime Detections

Runtime Detections

4 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: Propellerads can detect ad blocking and privacy tools, altering tracking behavior during security assessments to mask data collection scope.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Ad interaction patterns and engagement signals create behavioral profiles for audience targeting across network.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Tracking initializes across publisher properties regardless of consent state, processing visitor data before or without user permission.

BTI-C10Fingerprinting

Device identification

Impact: Device and browser fingerprinting creates persistent identifiers for visitor recognition across publisher network.

IOC Manifest

IOC Manifest

85 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*propellerads.com/wp-content/cache/wpo-minify/*/assets/wpo-minify-header-*.js*
Tracking script
TRACK
*propellerads.com/wp-content/cache/wpo-minify/*/assets/wpo-minify-footer-*.js*
Tracking script
TRACK
propellerads.com/wp-content/cache/wpo-minify/1768994832/assets/wpo-minify-header-51fd0673.min.js
Auto-extracted from scan
TRACK
propellerads.com/wp-content/cache/wpo-minify/1768994832/assets/wpo-minify-header-435018a1.min.js
Auto-extracted from scan
TRACK
propellerads.com/wp-content/cache/wpo-minify/1768994832/assets/wpo-minify-footer-b9dc2b0c.min.js
Auto-extracted from scan
TRACK
propellerads.com/wp-content/cache/wpo-minify/1768994832/assets/wpo-minify-footer-9a7b0969.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Propellerads integrates with publisher ad servers and monetization platforms. The vendor operates across a network of publisher properties, creating shared audience intelligence where visitor behavior on one site influences targeting on others. Integration architecture means publisher audience data flows to vendor infrastructure for cross-site profiling and campaign optimization.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

89 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details