Am I Being Pwned? logoAm I Being Pwned?
Book a demo
Home2FAS Auth Browser Extension
Findings · 3
LOW FINDINGS · 3
  1. 01Optional error-log beacon to api2.2fas.com includes the full current-page URL (path + query) with a trivially-reversible character substitution as obfuscation; OFF by default, on user toggle.
  2. 02Content script runs on every http/https page and in all frames (including about:blank) to enable 2FA OTP autofill into the focused input on user shortcut.
  3. 03The current tab's origin (scheme+host+port) is POSTed to api2.2fas.com when the user requests a 2FA code so the paired phone can pick the matching saved service.
OTHER EXTENSIONS

Is 2FAS Auth Browser Extension safe?

Low risk

No summary available.

Two Factor Authentication Service Inc.v1.8.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.twofas.org.browser.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact