Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeІІТ Користувач ЦСК-1. Бібл. підп. (web-р.)
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content script on all HTTP/HTTPS/file URLs relays arbitrary postMessage JSON-RPC commands to local NMH ua.com.iit.eusign.nmh; any page can initiate signing operations after a one-time user confirm
  2. 02Extension ID injected as <object> className into document.head on all HTTP/HTTPS/file pages, enabling fingerprinting by any page script
  3. 03Content script on all HTTP/HTTPS/file pages injects <object class='jffafkigfgmjafhpkoibhfefeaebmccg'> into DOM, exposing extension presence to any page script
OTHER EXTENSIONS

Is ІІТ Користувач ЦСК-1. Бібл. підп. (web-р.) safe?

Medium risk

No summary available.

JSC IITv1.3.1.11Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026jffafkigfgmjafhpkoibhfefeaebmccg

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact