Appearance
Why It Matters
Browser profile files such as cookies, saved logins, and browser state databases can contain live sessions and authentication material. Sending them off-host is high-confidence account theft behavior.
What Triggers
SEC696 matches executable hook lines that access browser profile paths together with secret-store files like Cookies, Login Data, logins.json, key4.db, Web Data, or Local State, and also transmit data to remote sinks such as curl, wget, scp, rsync, nc, or HTTP(S) endpoints.
False Positives
Shared committed hooks should not collect and transmit browser credential or cookie store data. Any local diagnostic or migration task that truly needs browser data should stay out of repo-shared automation.
Remediation
Remove network exfiltration of browser credential and cookie store data from the shared hook and keep browser profile data local.