why would you want to log the loginpass, it would have been already checked in member.php at the top and it would also compromise security and defeat the purpose of md5 thoughout the 2.2.x series.
Though the simpliest way to check if its a cookied login or not is the fact that the cookie wouldn't have been set yet meaning that $HTTP_COOKIE_VARS[bbuserid] and bbpassword and bbstyleid and bblastvisit will have just been set but they aren't taken into account until a page is loaded after they have been sent.
In case you didn't know if you send a cookie it won't take effect until after the page is reloaded, hence all the transition pages in vBulletin.