Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeMooltipass Extension
Findings · 3
LOW FINDINGS · 3
  1. 01Plaintext WebSocket to localhost daemon (ws://127.0.0.1:30035) used to ferry per-site credentials between extension and Moolticute companion daemon
  2. 02Content script runs on every http/https page (manifest matches `http://*/*`, `https://*/*`, all_frames:true, run_at document_idle) and sends the page origin to the Moolticute daemon for credential lookup
  3. 03"Report Error" toolbar action constructs a Google Forms URL with the current tab URL embedded as a query parameter and opens it in a new tab
OTHER EXTENSIONS

Is Mooltipass Extension safe?

Low risk

No summary available.

Stephan Electronicsv1.4Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.stephan-electronics.Mooltipass-Extension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact