Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeAli Reviews
Findings · 3
+3 more findings locked
CRITICAL FINDINGS · 3
  1. 01Service worker fetches JavaScript from priv.kudosi.ai and executes it in the MAIN world of any active tab
  2. 02webRequest.onSendHeaders intercepts Etsy and DSers HTTP request headers including CSRF tokens and session headers, stores them in chrome.storage.local and memory, then relays them to trusted external origins on request
  3. 03Shop authentication tokens stored by the extension are readable and writable by any page on externally_connectable origins via onMessageExternal GET_AUTH_TOKEN/SET_AUTH_TOKEN
+3 more findings locked
OTHER EXTENSIONS

Is Ali Reviews safe?

Critical risk

No summary available.

v7.1.3.0Chrome Web Store
100Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026bbaogjaeflnjolejjcpceoapngapnbaj

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact