Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeKarma | New browser extension
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01On retailer landing, content script inspects document.referrer and query params and the background marks the tab as 'competitor referrer' if the user arrived via a competing cashback extension (Honey, Rakuten, Capital One Shopping, RetailMeNot, Klarna, Avast SafePrice, Coupert, Smarty, Wikibuy, Piggy, Cuponation, Letyshops, iGraal, Avira, Coupon Mate, BravoDeal, ShopperApp, hellojoko, AliExitem); this drives downstream affiliate-attribution override (cookie/last-click stuffing).
  2. 02Background fetches a remote selector A/B-test config from karmacash.s3.amazonaws.com/selectors.json and a remote rules table from shoptagrapp.s3.eu-west-1.amazonaws.com/shorter_rules.json; both are then used to drive content-script scraping on third-party retailer pages.
  3. 03Content script on *://*/* sends host+href of every navigated page to background, which forwards full URL (path + query) to api/v2/rules on karmanow.com whenever the domain matches a retailer rule.
+2 more findings locked
OTHER EXTENSIONS

Is Karma | New browser extension safe?

Low risk

No summary available.

Shoptagr LTDv10.84.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.shoptagr.desktopSWE.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact