Am I Being Pwned? logoAm I Being Pwned?
Book a demo
Home2FAS Pass Browser Extension
Findings · 3
+3 more findings locked
LOW FINDINGS · 3
  1. 01Hardcoded HTTP Basic credential 2faspass:Vu8S0rz2A16I9E9K (base64 MmZhc3Bhc3M6VnU4UzByejJBMTZJOUU5Sw==) embedded in background.js and shipped to all installs to authenticate against https://log.2fas.com/loki/api/v1/push (Grafana Loki ingest)
  2. 02Browser, OS-derived and version metadata are POSTed to a vendor-operated Grafana Loki endpoint as part of error reporting, with no privacy disclosure surface on the install page
  3. 03Extension dynamically injects content-scripts/content.js into every http(s) tab on user action via chrome.scripting.executeScript with allFrames:true to perform login/credit-card autofill matching
+3 more findings locked
OTHER EXTENSIONS

Is 2FAS Pass Browser Extension safe?

Low risk

No summary available.

Two Factor Authentication Service Inc.v1.8.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.twofas.org.passbrowser.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact