Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeMobileMind
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content script injected on all pages transmits user session data and course state to admin.mobilemind.io API endpoints
  2. 02External message listener accepts auth tokens and user identity data from any mobilemind.io or devteamafterdark.com page without validating sender identity beyond domain
  3. 03Extension captures visible tab screenshots and transmits them to admin.mobilemind.io as course assessment evidence
OTHER EXTENSIONS

Is MobileMind safe?

Medium risk

No summary available.

devv5.2.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026dnjfcfcbcakfikppoeepnjjpoplhngjj

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact