Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePolinc Browser Extension
Findings · 3
HIGH FINDINGS · 3
  1. 01Captured login credentials are written to document.cookie on every visited site (any host the user submits a login form on), encrypted only with a hardcoded AES passphrase shipped in the extension, with no HttpOnly/Secure flag.
  2. 02Content script enumerates email/username/password inputs across the top document, every same-origin iframe, and every shadow DOM on every page (matches: <all_urls>) every 2 seconds, and queries the polinc backend with the page hostname on each navigation.
  3. 03Hardcoded AES passphrase shipped in the bundle is used to derive the only key protecting the credential cookies above; the same string protects every install.
OTHER EXTENSIONS

Is Polinc Browser Extension safe?

High risk

No summary available.

Proof of life incv1.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.polinc.browserextension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact