Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeRevBits PAM Extension
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Content script on <all_urls> reads every keystroke in detected username/password fields and persists the running username+password values to chrome.storage.local on every input/keyup/paste event
  2. 02Master password is stretched with only 1000 iterations of SHA-512 (server-sent passHash) and 1000 iterations of PBKDF2-SHA256 (local key derivation) — well below modern OWASP guidance
  3. 03Background sends device fingerprint (machine UDID, OS string, full User-Agent) to the user-configured PAM server during every login, 2FA verification, refresh, and inventory call
+1 more finding locked
OTHER EXTENSIONS

Is RevBits PAM Extension safe?

Medium risk

No summary available.

RevBitsv1.3.66Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.revbits.RevBits-PAM-Integration.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact