Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeLikeey
Findings · 3
+3 more findings locked
CRITICAL FINDINGS · 3
  1. 01declarativeNetRequest rules forge Origin and Sec-Fetch-* headers on all XHR requests to instagram.com and facebook.com, bypassing CORS and CSRF protections
  2. 02Extension extracts Instagram session tokens (csrf_token, userID, X-IG-D, LSD) and performs authenticated like mutations via GraphQL
  3. 03Extension extracts Facebook session tokens (fb_dtsg, lsd, CSRF, DTSG) from page HTML and uses them to perform authenticated GraphQL mutations
+3 more findings locked
OTHER EXTENSIONS

Is Likeey safe?

Critical risk

No summary available.

Likeeyv4.4Chrome Web Store
100Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ffadpiabilbnjbgcemdndlkikhmnniel

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact