Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeJumpCloud Password Manager
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Activity log telemetry sends credential interaction events (reveal, copy, autofill) with credential UUID, nickname, userAgent, and deviceUuid to JumpCloud cloud servers on every user action
  2. 02Native messaging to com.myki.daemon local desktop app bridges credential requests and vault sync operations; content script runs on all URLs
  3. 03Content script window.postMessage handler accepts messages without validating event.origin, allowing any page script to trigger keyboard navigation actions in extension-injected UI elements
OTHER EXTENSIONS

Is JumpCloud Password Manager safe?

Low risk

No summary available.

JumpCloudv2.5.8Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026dakjaeligofcdjlcoifkiappabgladep

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact