x-article-draft-uploader

Fail

Audited by Socket on Aug 16, 2026

1 alert found:

Malware
MalwareHIGH
scripts/export_x_cookies_from_chrome.py

This module is a focused Chrome cookie extraction and decryption utility. It obtains the Chrome Safe Storage password from the OS keychain, decrypts v10/v11 cookie values from the local Chrome Cookies SQLite database, filters to x.com/twitter.com, and writes plaintext cookie data to a local JSON file with restrictive permissions. While the fragment shows no network exfiltration, the implemented behavior is high-impact credential/session material harvesting and local persistence, making it very dangerous in a software supply chain scenario.

Confidence: 86%Severity: 94%
Audit Metadata
Analyzed At
Aug 16, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/mcncarl%2Fyichen-skills%2Fx-article-draft-uploader%2F@607877c78eb45c0911d16f30c5fa6fd228969c184c8104e2aaeaa5f8822ca875
Security Audit — socket — x-article-draft-uploader