A popup on YouTube downloader https://en.loader[.]to/4/ leads to wnouncillorswhowish.com, which redirects to playerhit.co, ending on the website depicted in the screenshot: https://l.gamerdenz.com/opera/player/ with a ton of query parameters.
If you remove those query parameters, the fake popup still shows but is broken: (behind CloudFlare): https://tria.ge/260606-wp1lnsbs7x/behavioral1
Clicking on the popup leads, eventually, to this OperaGX affiliate page: https://www.opera.com/get/opera-gx?utm_medium=pa&utm_campaign=PWN_US_HVR_9571_WEB_1977&utm_id=06a9d97b17374b1da991b7ca31d795f7&utm_source=PWNgames&edition=std-2
I have reported this to Opera via their online contact form—I could not find a specific abuse reporting email or form—and am waiting a response.







