Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomePrimus
Findings · 3
+1 more finding locked
HIGH FINDINGS · 3
  1. 01webRequest API intercepts request headers (including auth tokens and cookies) from ALL browser tabs during attestation flow and relays them through a WASM ZK-proof engine connected to wss://api.padolabs.org/algoproxy
  2. 02padoZKAttestationJSSDK.bundle.js content script injected on ALL URLs relays window.postMessage commands to background service worker without validating message origin
  3. 03Extension replays captured authenticated HTTP requests using stored auth headers (credentials:include) to private Binance/OKX account API endpoints to verify financial data before generating ZK proof
+1 more finding locked
OTHER EXTENSIONS

Is Primus safe?

High risk

No summary available.

Primus Labsv0.3.46Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026oeiomhmbaapihbilkfkhmlajkeegnjhe

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact