Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAegisWeb3
Findings · 3
+1 more finding locked
HIGH FINDINGS · 3
  1. 01simulation.js injects bundle.js into every page and proxies window.ethereum to capture DeFi transaction data sent to approve.aegisweb3.com/api/User/simulation
  2. 02Content script sends full URL of every page visited to approve.aegisweb3.com via background fetch
  3. 03On install, background.js extracts an 's2' referral parameter from any open tab URL containing the extension ID and sends it to approve.aegisweb3.com/api/User/PluginData
+1 more finding locked
OTHER EXTENSIONS

Is AegisWeb3 safe?

Medium risk

No summary available.

AegisWeb3v0.7.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026dakkielolpafjbgnjnakddabmbbkcioe

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact