Duolingo PRO was reported 2026-08-05 for Malware

The reporter said:

Steals Duolingo JWT/session token and sends it to api.duolingopro.net, allowing full account takeover.

This script has been updated since the report was filed.

This script has had 2 previous upheld or fixed reports.

anonymoushackerIV (the reported user) has made:

interstellar (the reported user) has made:

This report has been upheld by a moderator, but the moderator marked it as Missing, non-informative, or misleading description.

Although there's no evidence of malware but the description should explicitly mention this or the code should be reworked to make requests directly from the webpage