Is GoStream - Facebook LIVE safe?
GoStream - Facebook LIVE copies every Facebook cookie, including the session token, into a clipboard-ready block with one click.
When its popup opens, GoStream reads every cookie scoped to facebook.com, including the login-authenticating session cookie, and concatenates them with the browser's user agent into a base64-encoded string. A visible "Copy" button places that encoded cookie blob on the clipboard so the user can paste it into another application. The extension does not send this data anywhere on its own; it only prepares and copies it locally.
Who publishes itGoStream - 1 other listing from the same operator, 1 of them carrying a finding
GoStream - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 2k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
GoStream Facebook LIVE copies your full Facebook session cookies to clipboard
Code analysis shows GoStream Facebook LIVE reads every Facebook cookie in your browser, including the session-authenticating xs cookie, and stages the full set, base64-encoded, behind a one-click Copy button.
You open the GoStream extension's popup while already signed into facebook.com.
No further clicks are required; the popup runs this on load.
The popup reads your entire Facebook cookie jar and stages it, base64-encoded, behind a one-click Copy button.
This includes the auth-bearing xs session cookie and the c_user account ID, not a single identifier.
| Field | Value | Why it matters | |
|---|---|---|---|
Facebook session cookie (xs) | xs=17%3AaBcD3fGhIjKlMnOpQr%3A2%3A1234567890%3A88%3A9999 (illustrative) | Lets whoever pastes this blob act as your Facebook account until you log out or it expires. | |
Facebook account ID (c_user) | c_user=100003847562910 (illustrative) | Identifies which Facebook account the session belongs to. | |
Every other Facebook cookie | datr=AbCdEfGhIjKlMnOpQrStUvWx; sb=YzXwVuTsRqPoNmLkJiHgFe (illustrative) | Ad, analytics, and preference cookies are swept in with the session cookie, not filtered out. | |
Your browser's user agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/128.0.0.0 Safari/537.36 | Appended to the blob so whoever receives it can present the same browser identity as you. |
The cookie string is base64-encoded before it reaches the Copy field, so the input shows an opaque blob rather than readable cookie names.
c_user=100003847562910;xs=17%3AaBcD3fGhIjKlMnOpQr%3A2%3A1234567890%3A88%3A9999;datr=AbCdEfGhIjKlMnOpQrStUvWx;sb=YzXwVuTsRqPoNmLkJiHgFe;fr=0aBcDeFgHiJkLmNoPqRs.AWU1234567890abcdefg.BXy9Za.AAA.0.0.Bcde.fGhI;|||Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
The popup harvests the cookie jar, then encodes it for copy
// Fetches a single named cookie for a domain, used only to check Facebook login.
function getCookie(domain, name, callback) {
try {
chrome.cookies.get({ url: domain, name }, function (cookie) {
if (cookie && callback) callback(cookie.value);
else callback("");
});
} catch (e) {
alert(e);
}
}
// Fetches EVERY cookie scoped to a domain, not a single value.
function getCookies(domain, callback) {
try {
chrome.cookies.getAll({ url: domain }, function (cookie) {
if (cookie && callback) callback(cookie);
else callback([]);
});
} catch (e) {
alert(e);
}
}
// Confirms the user is logged into Facebook via the c_user cookie.
getCookie("https://facebook.com", "c_user", (cookie) => {
if (cookie) {
fb_id = cookie;
return;
}
alert("Please login on Facebook");
chrome.tabs.create({ url: "https://facebook.com" });
});
// Reads the FULL facebook.com cookie jar, including the auth-bearing "xs"
// session cookie, joins every name=value pair, appends the browser's user
// agent, and base64-encodes the result into the popup's Copy field.
getCookies("https://facebook.com", (cookies) => {
fb_cookies = "";
for (let item of cookies) {
fb_cookies += `${item.name}=${item.value};`; // e.g. "xs=...;c_user=...;"
}
document.getElementById("script_code").value =
btoa(`${fb_cookies}|||${navigator.userAgent}`);
});Base64-decodes the blob GoStream Facebook LIVE puts in its Copy field, back into individual cookie name/value pairs and the captured user agent.
#!/usr/bin/env python3
"""Decode the base64 blob GoStream Facebook LIVE writes into its popup's
disabled input field, splitting it back into individual Facebook cookie
name/value pairs plus the captured browser user agent string."""
import base64
import sys
def decode_blob(blob: str) -> None:
raw = base64.b64decode(blob).decode("utf-8", errors="replace")
cookie_part, _, user_agent = raw.partition("|||")
print("User agent:", user_agent)
print("Cookies:")
for pair in cookie_part.split(";"):
pair = pair.strip()
if not pair:
continue
name, _, value = pair.partition("=")
print(f" {name} = {value}")
if __name__ == "__main__":
if len(sys.argv) != 2:
print("usage: python3 decode_gostream_blob.py <base64-blob-from-copy-field>")
sys.exit(1)
decode_blob(sys.argv[1])
- 1Open the extension popup while signed into Facebook.
- 2Copy the value shown in the input field.
- 3Run python3 decode_gostream_blob.py <blob> to see each cookie and the user agent.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on facebook.com
*://*.facebook.com/*
Read and change cookies, including the ones that keep you signed in
cookies