Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeLumaly - Gutscheine & Cashback
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Background service worker fetches and executes per-shop JSON automation scripts from remote CDN https://files.lumaly.de/ext/js/ at runtime to drive content script DOM automation
  2. 02Extension reads checkout page cart totals, order IDs, and applied coupon codes across all e-commerce sites and exfiltrates them to api.lumaly.de/api/actions/purchase-totals
  3. 03Extension assigns a persistent per-user 'lead_id' tracking identifier on install and links it to browsing/purchase activity across all supported shops
+2 more findings locked
OTHER EXTENSIONS

Is Lumaly - Gutscheine & Cashback safe?

High risk

No summary available.

Lumalyv3.0.2.2Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ebgofhigpedaepplnmglnedbfjemmpnh

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact