Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeAmplitude Event Explorer
Findings · 3
HIGH FINDINGS · 3
  1. 01Content script on all pages can activate rrweb-based session recording (100% sample rate) that transmits full DOM mutations, clicks, and form interactions to Amplitude's servers
  2. 02Service worker reads the user's analytics.amplitude.com cookie (amp_* cookie containing device ID and base64-encoded user ID) on startup to correlate the extension operator's Amplitude identity
  3. 03Content script on all pages captures a full rrweb DOM snapshot plus page metadata (URL, scroll position, title) and transmits it to app.amplitude.com via an authenticated proxy when user clicks 'Open in Amplitude' from the zoning overlay
OTHER EXTENSIONS

Is Amplitude Event Explorer safe?

High risk

Amplitude Event Explorer intercepts all outgoing browser requests to extract analytics payloads and can activate full DOM session recording on any page.

Amplitudev1.7.1Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026acehfjhnmhbmgkedjmjlobpgdicnhkbp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact