Password_manager_tracking in www.paypalobjects.com

On 2020-04-30T09:38:49.303400+00:00 we found pattern Password_manager_tracking, type: User tracking and fingerprinting, (User email tracking by creating a fake login form and extracting user email filled in by a password manager) in the page https://www.paypalobjects.com/web/res/0… referenced from https://www.paypal.com/webapps/hermes?f… .

Code sample:

b'.createElement("form")' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.appendChild(' … b'.createElement("input")' … b' type="email"' … b' type="email"' … b' type="password"' … b' type="password"' … b' name="password"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!