Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeDigitalPersona
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Service worker fetches connection parameters including SRP credentials from local DigitalPersona agent on 127.0.0.1:52181, then establishes AES-encrypted WebSocket session to forward captured credential data
  2. 02Content script scans all web pages for login forms, captures input field values (username, password) and page URL, relaying them to the service worker
  3. 03Service worker handles chrome.runtime.onMessageExternal, allowing any external extension to query whether DigitalPersona is connected and to trigger a local agent reconnect
OTHER EXTENSIONS

Is DigitalPersona safe?

Low risk

No summary available.

DigitalPersona, Inc.v4.0.0.325Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026piimgpjgnagkckjlhjcppbkbjjfjmnbh

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact