Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeLusha - Easily find B2B contact information
Findings · 3
HIGH FINDINGS · 3
  1. 01v10.9.0 activates previously-dormant HubSpot scraping by adding https://*.hubspot.com/* to host_permissions AND content_scripts.matches. The HubspotScript content script (present but unreachable in v10.5.4 because the manifest did not match hubspot.com) now runs on every HubSpot page and forwards the scraped contact/company HTML to api.lusha.com via the existing Lusha iframe data flow.
  2. 02Six postMessage handlers across content.js, popup.js, and permission.js lack origin validation enabling untrusted page message injection
  3. 03LinkedIn and Salesforce profile data transmitted to Lusha backend for contact enrichment
OTHER EXTENSIONS

Is Lusha - Easily find B2B contact information safe?

High risk

No summary available.

LushaChromev10.5.4Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026mcebeofpilippmndlpcghpmghcljajna

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact