Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeQui-Quo
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Quick Login feature retrieves encrypted passwords from extension.qui-quo.ru/info/get-password and injects them into login forms on third-party travel operator booking sites; the agency's addonGuid and managerId are sent with every password request
  2. 02Service worker fetches remote content-scripts.json from extension.qui-quo.ru and dynamically injects the returned JS into all tabs on every navigation
  3. 03UON CRM API key captured from content script and transmitted to extension.qui-quo.ru/agency/uon/api-key
+2 more findings locked
OTHER EXTENSIONS

Is Qui-Quo safe?

High risk

No summary available.

Qui-Quov2.1.21Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026bcfkiidkpkfdmdnmafkkhffacoeapeed

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact