Is GoStream - Facebook LIVE safe?

High risk

GoStream - Facebook LIVE copies every Facebook cookie, including the session token, into a clipboard-ready block with one click.

When its popup opens, GoStream reads every cookie scoped to facebook.com, including the login-authenticating session cookie, and concatenates them with the browser's user agent into a base64-encoded string. A visible "Copy" button places that encoded cookie blob on the clipboard so the user can paste it into another application. The extension does not send this data anywhere on its own; it only prepares and copies it locally.

gostream.cov0.2Chrome Web Store
75Risk
Who publishes it

GoStream - 1 other listing from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
gostream.co
Declared legal entity
GoStream

Same store account

1 other listing published from this account, 2k+ users between them. 1 of them carries a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityCRITICAL
ClassUNWANTED
TypeUnexpected
CWECWE-522
SourceAI FOUND

GoStream Facebook LIVE copies your full Facebook session cookies to clipboard

Code analysis shows GoStream Facebook LIVE reads every Facebook cookie in your browser, including the session-authenticating xs cookie, and stages the full set, base64-encoded, behind a one-click Copy button.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the GoStream extension's popup while already signed into facebook.com.

No further clicks are required; the popup runs this on load.

The extension did this

The popup reads your entire Facebook cookie jar and stages it, base64-encoded, behind a one-click Copy button.

This includes the auth-bearing xs session cookie and the c_user account ID, not a single identifier.

02EvidenceFIELD TABLE
What the copied blob contains
FieldValueWhy it matters
Facebook session cookie (xs)
xs=17%3AaBcD3fGhIjKlMnOpQr%3A2%3A1234567890%3A88%3A9999 (illustrative)Lets whoever pastes this blob act as your Facebook account until you log out or it expires.
Facebook account ID (c_user)
c_user=100003847562910 (illustrative)Identifies which Facebook account the session belongs to.
Every other Facebook cookie
datr=AbCdEfGhIjKlMnOpQrStUvWx; sb=YzXwVuTsRqPoNmLkJiHgFe (illustrative)Ad, analytics, and preference cookies are swept in with the session cookie, not filtered out.
Your browser's user agent
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/128.0.0.0 Safari/537.36Appended to the blob so whoever receives it can present the same browser identity as you.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The cookie string is base64-encoded before it reaches the Copy field, so the input shows an opaque blob rather than readable cookie names.

What's actually being sent
c_user=100003847562910;xs=17%3AaBcD3fGhIjKlMnOpQr%3A2%3A1234567890%3A88%3A9999;datr=AbCdEfGhIjKlMnOpQrStUvWx;sb=YzXwVuTsRqPoNmLkJiHgFe;fr=0aBcDeFgHiJkLmNoPqRs.AWU1234567890abcdefg.BXy9Za.AAA.0.0.Bcde.fGhI;|||Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
04EvidenceCODE COMPARE
The code that does this

The popup harvests the cookie jar, then encodes it for copy

What it actually does
// Fetches a single named cookie for a domain, used only to check Facebook login.
function getCookie(domain, name, callback) {
  try {
    chrome.cookies.get({ url: domain, name }, function (cookie) {
      if (cookie && callback) callback(cookie.value);
      else callback("");
    });
  } catch (e) {
    alert(e);
  }
}

// Fetches EVERY cookie scoped to a domain, not a single value.
function getCookies(domain, callback) {
  try {
    chrome.cookies.getAll({ url: domain }, function (cookie) {
      if (cookie && callback) callback(cookie);
      else callback([]);
    });
  } catch (e) {
    alert(e);
  }
}

// Confirms the user is logged into Facebook via the c_user cookie.
getCookie("https://facebook.com", "c_user", (cookie) => {
  if (cookie) {
    fb_id = cookie;
    return;
  }
  alert("Please login on Facebook");
  chrome.tabs.create({ url: "https://facebook.com" });
});

// Reads the FULL facebook.com cookie jar, including the auth-bearing "xs"
// session cookie, joins every name=value pair, appends the browser's user
// agent, and base64-encodes the result into the popup's Copy field.
getCookies("https://facebook.com", (cookies) => {
  fb_cookies = "";
  for (let item of cookies) {
    fb_cookies += `${item.name}=${item.value};`; // e.g. "xs=...;c_user=...;"
  }
  document.getElementById("script_code").value =
    btoa(`${fb_cookies}|||${navigator.userAgent}`);
});
05EvidenceARTIFACT
Check if you're affected

Base64-decodes the blob GoStream Facebook LIVE puts in its Copy field, back into individual cookie name/value pairs and the captured user agent.

RequiresPython 3
decode_gostream_blob.py · py
#!/usr/bin/env python3
"""Decode the base64 blob GoStream Facebook LIVE writes into its popup's
disabled input field, splitting it back into individual Facebook cookie
name/value pairs plus the captured browser user agent string."""
import base64
import sys


def decode_blob(blob: str) -> None:
    raw = base64.b64decode(blob).decode("utf-8", errors="replace")
    cookie_part, _, user_agent = raw.partition("|||")
    print("User agent:", user_agent)
    print("Cookies:")
    for pair in cookie_part.split(";"):
        pair = pair.strip()
        if not pair:
            continue
        name, _, value = pair.partition("=")
        print(f"  {name} = {value}")


if __name__ == "__main__":
    if len(sys.argv) != 2:
        print("usage: python3 decode_gostream_blob.py <base64-blob-from-copy-field>")
        sys.exit(1)
    decode_blob(sys.argv[1])
How to run it
  1. 1
    Open the extension popup while signed into Facebook.
  2. 2
    Copy the value shown in the input field.
  3. 3
    Run python3 decode_gostream_blob.py <blob> to see each cookie and the user agent.
06EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on facebook.com

    *://*.facebook.com/*

  • Read and change cookies, including the ones that keep you signed in

    cookies

Updated 30 September 2026lbjpjieeknbajhkbagkefffecemcjhhg