Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeINSSIST | Web Client for Instagram
Findings · 3
+5 more findings locked
MEDIUM FINDINGS · 3
  1. 01New in v38.1.2: fusion config response can include an mscr key with a search query string; the extension then silently queries Instagram's music search API and POSTs the resulting track metadata (id, artist, name, cover) to api.inssist.com/api/v1/mscr/tracks?auto
  2. 02Remote config endpoint can update extension settings and trigger runtime reload without a CWS update
  3. 03When user clicks ADD USERNAME in the account switcher, the extension opens api.inssist.com/manage?token=<billing_token> in a new tab, exposing the auth token in browser history, server logs, and referrer headers
+5 more findings locked
OTHER EXTENSIONS

Is INSSIST | Web Client for Instagram safe?

Medium risk

No summary available.

inssist.comv36.2.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+5 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026bcocdbombenodlegijagbhdjbifpiijp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact