cookie

Fail

Audited by Socket on Jul 2, 2026

1 alert found:

Malware
MalwareHIGH
scripts/export-chrome-cookies.mjs

This module performs highly actionable cookie/session theft: it retrieves the macOS Keychain secret used by Chrome to decrypt cookies, reads and decrypts the local Chrome Cookies SQLite database, exports decrypted cookies in cleartext to /tmp, and generates a loader that can re-inject those cookies into an automated browser context (session replay/impersonation). Cleanup targets intermediate snapshots, not the exported secrets. Overall, this is strongly consistent with malicious credential/session harvesting.

Confidence: 93%Severity: 100%
Audit Metadata
Analyzed At
Jul 2, 2026, 10:16 AM
Package URL
pkg:socket/skills-sh/laststance%2Fskills%2Fcookie%2F@7ee3badb6013f16b11ddab69b148f3361b14f3fda3698712a40cd961f1dae97d
Security Audit — socket — cookie