Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCreator Insights - Social Media Distribution & Analytics tool
Findings · 3
+9 more findings locked
CRITICAL FINDINGS · 3
  1. 01XHR prototype hooks in script.js intercept all Instagram GraphQL API responses on every Instagram page load, capturing full post metadata including user data, engagement metrics, captions, and profile information.
  2. 02feedInterceptor.js hooks both XMLHttpRequest and fetch globally to intercept all Instagram and YouTube API responses, capturing full feed data including post content, engagement metrics, and author information.
  3. 03Hardcoded API access token exposed in 20+ locations across extension source files, and JWT auth tokens are transmitted to a third-party iframe via postMessage with wildcard origin.
+9 more findings locked
OTHER EXTENSIONS

Is Creator Insights - Social Media Distribution & Analytics tool safe?

Critical risk

No summary available.

sushanthspoojary777v9.811Chrome Web Store
100Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+9 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ephjpmehpeloidcfonclaabcfemmihfd

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact