Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCiti Shop℠
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Wildlink-driven SERP DOM injection on Google Search controlled by remote-fetched config; <all_urls> content_script fetches selectors+click handlers from dev-www.wildlink.me and prepends elements into google.com/search results
  2. 02Page innerText regex scores, page title, checkout URL and merchant ID exfiltrated to wildlink.me on partner-site checkout for purchase-confirmation tracking
  3. 03Active-domain DB and merchant-rates tables fetched from storage.googleapis.com (Wildlink's own GCS bucket) and used to gate every <all_urls> content-script behavior; compromise of that bucket controls which sites trigger purchase-confirmation scraping and which Google search results get decorated
+1 more finding locked
OTHER EXTENSIONS

Is Citi Shop℠ safe?

Medium risk

No summary available.

Citibankv1.26Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.citigroup.mac.citishop.safariExtension.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact