Is X Token Login safe?

High risk

X Token Login is high risk. Typing a token into the popup and clicking Login makes the extension set the auth_token cookie on x.com to that value, one-year expiry, via the scripting API, then navigate to x.com. This bypasses login: no OAuth, password, or validation.

75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-522
SourceAI SANDBOX

Popup UI injects arbitrary auth_token cookie directly into x.com

Typing a token into the popup and clicking Login makes the extension set the auth_token cookie on x.com to that value, one-year expiry, via the scripting API, then navigate to x.com.

This bypasses login: no OAuth, password, or validation.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You type a token into the extension popup and click Login.

The extension did this

The extension injects a Login function into your active x.com tab and sets the auth_token cookie to the value you entered.

The cookie is set with domain=x.com, path=/, a one-year expiry, and the Secure flag. The tab is then redirected to https://x.com.

02EvidenceCODE COMPARE
The code that does this

The extension's full source, popup listener and injected function

What it actually does
What the popup listener does
// Runs when user clicks the Login button in the popup.
// Reads whatever text is in the #token input, then injects the Login()
// function into the currently active tab (which must be open on x.com).
document.querySelector('#submit').addEventListener('click', function () {
  const token = document.querySelector('#token').value;  // raw user input, unvalidated
  chrome.tabs.query({ active: true, currentWindow: true }, function (tabs) {
    chrome.scripting.executeScript({
      target: { tabId: tabs[0].id },
      func: Login,      // the function defined below is injected into the x.com page
      args: [token]     // user-supplied token is passed as an argument
    });
  });
});
What Login() does inside the x.com tab
// Runs inside the x.com tab, not the popup.
// Sets the auth_token session cookie directly using document.cookie,
// bypassing any OAuth or server-side authentication.
function Login(token) {
  const expirationTime = new Date();
  expirationTime.setFullYear(expirationTime.getFullYear() + 1);  // 1 year from now

  // Writes auth_token to the x.com cookie jar:
  //   domain=x.com   → applies to all of x.com
  //   path=/         → applies to all paths
  //   Secure         → only sent over HTTPS
  //   expires        → session persists for 1 year unless explicitly cleared
  document.cookie = `auth_token=${token.replace('"', '')};domain=x.com;path=/;expires=${expirationTime.toUTCString()};Secure`;

  window.location.replace('https://x.com');  // navigate to x.com immediately after
}
03EvidenceFIELD TABLE
Cookie fields written to x.com by the Login function:
FieldValueWhy it matters
Cookie name
auth_tokenauth_token is the primary session cookie used by x.com to authenticate requests. Overwriting it replaces your existing session.
Cookie value
BEHAVIORAL_TEST_TOKEN_XYZ_12345Whatever you typed into the popup. No validation is performed, any string is accepted and written.
Cookie domain
x.comSet to x.com, so the cookie is sent to all of x.com.
Cookie expiry
Fri, 17 Apr 2027 06:36:51 GMTSet to one year from the moment of injection. The session persists until the cookie is manually cleared or overwritten.
04EvidenceARTIFACT
Reproduce it yourself

Paste this into DevTools on an x.com tab to confirm how the Login function works: it reads the current auth_token cookie before and after a simulated injection, showing that document.cookie is the only mechanism used.

RequiresChrome (any version with DevTools)An open tab on https://x.com
verify-x-token-login.js · js
// verify-x-token-login.js
// Reproduces the cookie injection performed by the X Token Login extension.
// Run in DevTools on any x.com tab (you must be on https://x.com or a subdomain).

(function () {
  // Helper: read the current auth_token cookie value
  function getAuthToken() {
    const match = document.cookie.match(/(?:^|;\s*)auth_token=([^;]*)/);
    return match ? decodeURIComponent(match[1]) : null;
  }

  console.log('[BEFORE] auth_token =', getAuthToken());

  // This is the exact function the extension injects:
  function Login(token) {
    var expirationTime = new Date();
    expirationTime.setFullYear(expirationTime.getFullYear() + 1);
    document.cookie = `auth_token=${token.replace('"', '')};domain=x.com;path=/;expires=${expirationTime.toUTCString()};Secure`;
    // NOTE: window.location.replace is intentionally omitted here so you can
    // observe the cookie change without a page reload.
  }

  // Inject a test token (replace with a real token to test actual login)
  const testToken = 'VERIFY_TOKEN_12345';
  Login(testToken);

  console.log('[AFTER]  auth_token =', getAuthToken());
  console.log('Cookie is now:', document.cookie);
  console.log('Observe: auth_token was overwritten without any request to x.com\'s auth endpoint.');
})();
How to run it
  1. 1
    Open Chrome, go to https://x.com.
  2. 2
    Open DevTools (F12), Console tab.
  3. 3
    Paste this script, press Enter.
  4. 4
    Console logs the auth_token value before/after injection.
  5. 5
    Check Application > Cookies > https://x.com to confirm it changed.

What it can do

Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on x.com

    https://x.com/*

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026lebmjgeajaflbnbggmpeibnpeonjlmgb