x-article-draft-uploader
Fail
Audited by Socket on Aug 16, 2026
1 alert found:
MalwareMalwarescripts/export_x_cookies_from_chrome.py
HIGHMalwareHIGH
scripts/export_x_cookies_from_chrome.py
This module is a focused Chrome cookie extraction and decryption utility. It obtains the Chrome Safe Storage password from the OS keychain, decrypts v10/v11 cookie values from the local Chrome Cookies SQLite database, filters to x.com/twitter.com, and writes plaintext cookie data to a local JSON file with restrictive permissions. While the fragment shows no network exfiltration, the implemented behavior is high-impact credential/session material harvesting and local persistence, making it very dangerous in a software supply chain scenario.
Confidence: 86%Severity: 94%
Audit Metadata