Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeApi4Com - Extensão para Navegadores
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01CRM contact data (name, phone numbers, entity IDs) exfiltrated to api.api4com.com when user clicks the dialer button on any of 23 supported CRM platforms
  2. 02Phone number and CRM extension credentials POSTed to api.api4com.com/api/v1/dialer on every call initiation, including contact URL and CRM entity metadata
  3. 03User's api4com session token stored in chrome.storage.sync as plain text and passed in URL query parameters as access_token to CRM integration endpoints
+2 more findings locked
OTHER EXTENSIONS

Is Api4Com - Extensão para Navegadores safe?

High risk

No summary available.

adminv4.28.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026nmihkcakhpccmdhoifppbgeoapjaanno

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact