Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeBuyhatke: Price History & Tracker, Spend Lens
Findings · 3
+13 more findings locked
HIGH FINDINGS · 3
  1. 01Service worker TRIGGER_SYNC handler forwards arbitrary extension payloads to a content script (addToCart.js) running on grocery sites (Blinkit, Zepto, JioMart, Swiggy Instamart, BigBasket, DMart, Flipkart, Amazon.in) which writes them into localStorage or IndexedDB (keyval-store) and triggers location.reload(), enabling cart/state manipulation without user interaction.
  2. 02New server-controlled page-scraping pipeline (dcCollect/dcStart) reads outerHTML and product data from any shopping page and posts it to ext1.buyhatke.com/spidy/response
  3. 03Sends user-entered email address to buyhatke.com when user submits email in extension UI
+13 more findings locked
OTHER EXTENSIONS

Is Buyhatke: Price History & Tracker, Spend Lens safe?

High risk

No summary available.

Buyhatkev5.1.128Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+13 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ojplmecpdpgccookcobabopnaifgidhf

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact