Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeBloxFinder - Join Anyone on Roblox
Findings · 3
MEDIUM FINDINGS · 3
  1. 01New exportInsert.js injects Re-Upload/Save-Template buttons across Roblox catalog that silently redirect to roexport.io — a second undisclosed affiliate domain not present in v26
  2. 02Undisclosed affiliate promotion replaces native Roblox purchase buttons with roearn.io redirects
  3. 03v26.1 adds externally_connectable matching *://*.roblox.com/* with no corresponding onMessageExternal/onConnectExternal handler in background.js — opens extension messaging surface to all roblox.com pages
OTHER EXTENSIONS

Is BloxFinder - Join Anyone on Roblox safe?

Medium risk

No summary available.

BloxFinderv26Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026bnpkdbbfehooennlcojneoimfjgekdgn

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact