Is Não Seguidores safe?

Medium risk

Não Seguidores is medium risk. Code analysis shows on an authenticated Instagram page, Nao Seguidores' content script reads session values from the page into API request headers. Unauthenticated, it showed "Login no Instagram nao detectado" with no API request.

invertexto.comv1.4.5Chrome Web Store
45Risk
Who publishes it

invertexto.com - 6 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
invertexto.com

Same store account

6 other listings published from this account, 199k+ users between them. 1 of them carries a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Instagram session values read for API requests

Code analysis shows on an authenticated Instagram page, Nao Seguidores' content script reads session values from the page into API request headers.

Unauthenticated, it showed "Login no Instagram nao detectado" with no API request.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You run the extension while already signed in to Instagram.

The background script opens Instagram and injects the content script after the page finishes loading.

The extension did this

The extension reads Instagram page and session values and prepares them as API request headers.

Without an authenticated Instagram page, the extension reports that no Instagram login was detected.

02EvidenceFIELD TABLE
Instagram values the content script reads and reuses
FieldValueWhy it matters
Your Instagram account ID
23816413978342712 (illustrative)This identifies which Instagram account the extension is acting on.
Your CSRF token
9kR3Yb0p7cH2Lq8Nf6QaV4Bm1Sd0 (illustrative)This helps authorize state-changing requests from your logged-in Instagram session.
Instagram app identifier
936619743392459 (illustrative)This tells Instagram which web app client the request is using.
Instagram rollout marker
1019693628 (illustrative)This adds version context for Instagram's web API requests.
Instagram web claim
hmac.AR2xYdHjWpVbQmS7nK4rTz (illustrative)This session value can tie API requests back to your active Instagram browser session.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.instagram.com/graphql/query/?query_hash=3dec7e2c57367ef3da3d987d89f9dbc8&variables={"id":"23816413978342712","include_reel":false,"fetch_mutual":false,"first":50,"after":""}
No GraphQL response was captured in the unauthenticated test; the extension requires a logged-in Instagram session before this request path runs.
Headers
X-Csrftoken9kR3Yb0p7cH2Lq8Nf6QaV4Bm1Sd0 (illustrative)
X-Ig-App-Id936619743392459 (illustrative)
04EvidenceNETWORK CAPTURE
Captured request
POSThttps://i.instagram.com/api/v1/web/friendships/23816413978342712/unfollow/
No unfollow response was captured in the unauthenticated test; the code sends this request after a listed account's Seguindo button is clicked.
Headers
X-Asbd-Id129477
X-Csrftoken9kR3Yb0p7cH2Lq8Nf6QaV4Bm1Sd0 (illustrative)
X-Ig-App-Id936619743392459 (illustrative)
Content-Typeapplication/x-www-form-urlencoded
X-Instagram-Ajax1019693628 (illustrative)
X-Requested-WithXMLHttpRequest
05EvidenceCODE COMPARE
The code that does this

The content script parses Instagram session values and copies them into headers

What it actually does
Readable token extraction and header assignmentcontentScript.js
const m = document.body.innerHTML,
  n = m.match(/\?"viewerId\?":\?"(\w+)\?"/i),
  o = m.match(/\?"appScopedIdentity\?":\?"(\w+)\?"/i),
  p = m.match(/(?<="csrf_token":").+?(?=")/i),
  q = m.match(/(?<="X-IG-App-ID":").+?(?=")/i),
  r = m.match(/(?<="rollout_hash":").+?(?=")/i);
let s = n ? n[1] : null;
s || (s = o ? o[1] : null);
const t = {},
  u = {
    "Content-Type": "application/x-www-form-urlencoded",
    "X-Requested-With": "XMLHttpRequest",
    "X-Asbd-Id": 129477,
  };
sessionStorage.getItem("www-claim-v2") &&
  (u["X-Ig-Www-Claim"] = sessionStorage.getItem("www-claim-v2"));
p && ((t["X-Csrftoken"] = p[0]), (u["X-Csrftoken"] = p[0]));
q && ((t["X-Ig-App-Id"] = q[0]), (u["X-Ig-App-Id"] = q[0]));
r && (u["X-Instagram-Ajax"] = r[0]);
06EvidenceTHIRD PARTY LIST
Hosts receiving the generated Instagram API requests
  • www.instagram.com

    Receives GraphQL follower-list requests with X-Csrftoken and X-Ig-App-Id headers.

  • i.instagram.com

    Receives friendship unfollow POST requests with CSRF, app, web-claim, and rollout headers.

What it can do

Permissions this extension asks for, as declared in version 1.3.15. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 1.4.5, which we have not unpacked yet.

  • Read and change your data on instagram.com

    https://*.instagram.com/*

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026ggnclhlkbhihgehcgmnckfgkjjkckbop