Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeEagle for Safari
Findings · 3
+3 more findings locked
MEDIUM FINDINGS · 3
  1. 01Calls Instagram's private mobile API i.instagram.com/api/v1/media/{id}/info/ with credentials:'include' and a runtime-extracted x-ig-app-id header to fetch authenticated video URLs as the logged-in Instagram user.
  2. 02Background fetches a remote-config JSON of CSS selector rules from https://oss-app.eagle.cool/extensions/batch-save-image-rules.json and then queries those selectors against the current page (Twitter, Pinterest, Xiaohongshu, Dribbble, Huaban, GameUI, Meiye, etc.) to enumerate every image/link/spinner element before exfiltrating to Eagle desktop.
  3. 03Hardcoded Twitter Bearer token combined with the user's ct0 CSRF cookie is used to call Twitter's internal authenticated /i/api/2/timeline/conversation/{tweet_id}.json endpoint to fetch video metadata as the logged-in user.
+3 more findings locked
OTHER EXTENSIONS

Is Eagle for Safari safe?

Medium risk

No summary available.

YiHao Chenv3.1.20Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026cool.eagle.extension.entity

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact