Which browser extension is recording my screen?
macOS attributes a screen recording to the application, never to the tab or extension behind it. Run npx am-i-being-recorded: it reads Chromium-family browser profiles (Chrome, Brave, Edge, Chromium, Vivaldi) and names each extension with display-capture, tab-capture or debugger permissions, with its ID, version and profile. Disable that extension at chrome://extensions and restart the browser.
Run it
npx am-i-being-recorded
It needs jq (brew install jq or apt-get install jq). It reads files on your machine and makes no network calls.
What the answer looks like
CRITICAL Example Screen Recorder (aaaabbbbccccddddeeeeffffgggghhhh) v1.2.3
Google/Chrome/Default - Can capture the entire display (screen recording)
HIGH Example Screen Recorder (aaaabbbbccccddddeeeeffffgggghhhh) v1.2.3
Google/Chrome/Default - Capture permission plus an offscreen document can outlive the visible tab
A "stuck" recording indicator is usually an extension holding a display stream from an offscreen document. Disable or remove it in chrome://extensions (or brave://extensions), then restart the browser so the indicator clears.
Permissions it flags
| Permission | Severity | Why |
|---|---|---|
desktopCapture | CRITICAL | Can record the entire display |
tabCapture | HIGH | Can record the active tab's audio and video |
debugger | HIGH | Full tab control over the DevTools protocol |
nativeMessaging | MEDIUM | Can launch a native helper process |
userScripts | MEDIUM | Can inject scripts into pages |
management | LOW | Can enable or disable other extensions |
Two combinations escalate: display capture with access to every site, and any capture permission with an offscreen document.
Other things that can capture you
On macOS it also prints context, not findings: whether the screen-sharing daemons are running, and which apps hold camera, microphone and screen-recording permission, each with its code signer and Team ID. An unsigned app with a capture permission is worth a look. Reading the screen-recording permissions needs root or Full Disk Access; the tool says so rather than guessing. On Linux it shows which process holds a camera device.
Limits
- It reports capability, not proof of an active stream. A recorder you installed on purpose is flagged too.
- Safari and Firefox extensions, standalone recorder apps, and a web page's own screen-share prompt are out of scope.
- It is triage that names a suspect, not a malware scanner.
Use --strict to make any finding exit 1, and --min-severity HIGH to show only the loud ones.