Is Fob safe?

Medium risk

Fob reads your full LinkedIn cookie set, including the li_at session cookie, and writes it into a form field on the vendor's own site.

When you click its "connect to LinkedIn" button, Fob's background script pulls every cookie for linkedin.com, including li_at (LinkedIn's long-lived session-authentication cookie), and hands the full set back to the page. The content script then writes that raw cookie JSON into an input field on fob.ai.cc/linkedinAccount, a page owned by the extension's own vendor, matching the extension's stated purpose of retrieving your LinkedIn session each time you use it.

eoseocnv1.0.0Chrome Web Store
45Risk
Who publishes it

eoseocn - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
eoseocn

Same store account

1 other listing published from this account, 297 users between them. 1 of them carries a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-522
SourceAI FOUND

Fob copies your entire LinkedIn cookie set into a field on its own page

Code analysis shows Fob reads every LinkedIn cookie, including the li_at session cookie, when you click its button on fob.ai.cc, then writes the full set into a form field on that page.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click Get LinkedIn Cookies on the fob.ai.cc account-linking page while logged into LinkedIn.

The button only appears on the vendor's own fob.ai.cc/linkedinAccount page.

The extension did this

The extension reads every LinkedIn cookie, including the li_at session cookie, and writes the full set into a field on that page.

The read happens in the background service worker; the write happens in the content script.

02EvidenceFIELD TABLE
Cookie fields chrome.cookies.getAll returns for a logged-in LinkedIn session (example values)
FieldValueWhy it matters
LinkedIn session cookie (li_at)
AQEDATmF3q0-abcd1234EFGH5678ijklMNOPqrst==Lets whoever holds it act as you on LinkedIn without your password, until you sign out everywhere.
Browser ID cookie (bcookie)
"2-9f3c1a2e-7b6d-4e11-8a2f-1d4c9b0a5e33"A long-lived identifier LinkedIn uses to recognize your browser across visits.
Load-balancer routing cookie (lidc)
"b=OGST07:s=O:r=O:a=O"Routes your requests to the same LinkedIn server; not tied to your identity on its own.
Language preference cookie (lang)
"v=2&lang=en-us"Stores your LinkedIn display language.
03EvidenceCODE COMPARE
The code that does this

Cookie read (background.js) and page write (content-script.js); ships unminified

What it actually does
Bulk cookie read on every request from the content scriptbackground.js
chrome.runtime.onMessage.addListener(function(request, sender, sendResponse) {
  new Promise(async (resolve, reject) => {
    let linkedin_url = 'https://www.linkedin.com/';
    chrome.cookies.getAll({ url: linkedin_url }, function (cookies) {
      let login = 0;
      const resList = cookies.map(item => {
        if (item.name == 'li_at') { login = 1; }
        return item;
      });
      const cookieJsonStr = JSON.stringify(resList);
      sendResponse({ is_login: login, cookie: cookieJsonStr });
    });
  });
  return true;
});
The response is written straight into a page-owned form fieldcontent-script.js
connect_to_linkedIn.onclick = async function(){
    chrome.runtime.sendMessage(
        { cookies: 'update', data: "hagro_linkedIn" },
        function(response) {
            if(response.is_login == 1){
                $('input[name="cookies"]').val(response.cookie);
                $("#connect_to_linkedIn").text('已获取Cookies');
                $("#connect_to_linkedIn").prop("disabled",true);
            }
        }
    );
};
04EvidenceARTIFACT
Reproduce it yourself

Pastes into DevTools on fob.ai.cc/linkedinAccount to watch the extension write LinkedIn cookies into the page field.

RequiresChrome with Fob installedAn active linkedin.com session
watch-fob-cookie-write.js · js
// Paste into the DevTools Console on https://fob.ai.cc/linkedinAccount
// BEFORE clicking the "Get LinkedIn Cookies" button.
const field = document.querySelector('input[name="cookies"]');
if (!field) {
  console.log('input[name="cookies"] not found on this page yet.');
} else {
  const desc = Object.getOwnPropertyDescriptor(HTMLInputElement.prototype, 'value');
  Object.defineProperty(field, 'value', {
    set(v) {
      console.log('[fob-cookie-write] field value set to:', v);
      desc.set.call(this, v);
    },
    get() { return desc.get.call(this); }
  });
  console.log('Watching input[name="cookies"]. Now click the button.');
}
How to run it
  1. 1
    Install Fob and log into LinkedIn.
  2. 2
    Open fob.ai.cc/linkedinAccount and open DevTools Console.
  3. 3
    Paste this script and press Enter.
  4. 4
    Click Get LinkedIn Cookies and read the logged field value.
05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on fob.ai.cc

    *://fob.ai.cc/*

  • Read and change your data on linkedin.com

    *://*.linkedin.com/*

  • Show you desktop notifications

    notifications

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • See the address and title of every tab you have open

    tabs

Where it sends data

Destinations our analysis observed Fob contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • fob.ai.cc

    Fob sends data to fob.ai.cc. No other extension we have analysed sends data here.

Updated 30 September 2026bcaclmklbiocjohhooaaldkbelkaogod