cookie
Fail
Audited by Socket on Jul 2, 2026
1 alert found:
MalwareMalwarescripts/export-chrome-cookies.mjs
HIGHMalwareHIGH
scripts/export-chrome-cookies.mjs
This module performs highly actionable cookie/session theft: it retrieves the macOS Keychain secret used by Chrome to decrypt cookies, reads and decrypts the local Chrome Cookies SQLite database, exports decrypted cookies in cleartext to /tmp, and generates a loader that can re-inject those cookies into an automated browser context (session replay/impersonation). Cleanup targets intermediate snapshots, not the exported secrets. Overall, this is strongly consistent with malicious credential/session harvesting.
Confidence: 93%Severity: 100%
Audit Metadata