Duolingo PRO was reported 2026-08-05 for Malware
The reporter said:
Steals Duolingo JWT/session token and sends it to api.duolingopro.net, allowing full account takeover.
This script has been updated since the report was filed.
This script has had 2 previous upheld or fixed reports.
anonymoushackerIV (the reported user) has made:
interstellar (the reported user) has made:
This report has been upheld by a moderator, but the moderator marked it as Missing, non-informative, or misleading description.
Although there's no evidence of malware but the description should explicitly mention this or the code should be reworked to make requests directly from the webpage
