Duolingo PROa été signalé 05/08/2026 pour Malware

Le rapport dit :

Steals Duolingo JWT/session token and sends it to api.duolingopro.net, allowing full account takeover.

Ce script a été mis à jour depuis le dépôt du rapport.

Ce script a déjà fait l'objet de 2 rapports confirmés ou corrigés.

anonymoushackerIV(l'utilisateur signalé) a effectué:

interstellar(l'utilisateur signalé) a effectué:

Ce rapport a été confirmé par un modérateur, mais le modérateur l'a marqué comme Description manquante, non informative ou trompeuse.

Although there's no evidence of malware but the description should explicitly mention this or the code should be reworked to make requests directly from the webpage