Malware News New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies

Security News
1 Reply 133 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies.

The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook.

The archive included a “TokenGrabber Builder” folder containing a Python builder and an embedded stealer payload.

The structure points to a malware-as-a-service (MaaS) model, allowing multiple affiliates or low-skilled operators to build and deploy individualized samples.

The builder can compile the embedded Python payload into Windows executables using Nuitka or PyInstaller, or save it as a raw Python script.

Nuitka is especially notable because it converts Python code into native binaries, reducing the presence of recoverable Python bytecode and complicating analysis with common Python decompilers.

Before compilation, the operator supplies a Discord or Telegram webhook address. The builder XOR-encrypts the address with key 0x5A, Base64-encodes it and injects it into the payload.

This approach prevents the webhook from appearing in plaintext and causes separately built samples to carry different encoded configuration values and potentially distinct hashes, weakening simple indicator-based clustering.

The builder also automatically installs dependencies when needed and searches for locally installed Python interpreters through environment paths, common installation directories and Windows Registry locations.
Read more:
 
A Python-based information stealer reportedly targets 17 Chromium-based browsers and Firefox, harvesting credentials, payment-card details, history and session cookies. Its builder can generate customized Windows payloads and send stolen data through operator-supplied Discord or Telegram webhooks.


Hi, this describes a configurable infostealer builder rather than evidence of a new browser vulnerability. A victim would still need to run a generated payload—or otherwise have code executed on the PC—for it to reach locally stored browser data.

What matters in practice​

Stolen session cookies are especially important because they may let an attacker reuse an authenticated session without knowing the password. MFA remains valuable, but it does not necessarily stop theft and replay of a session that has already passed MFA checks.

The builder details explain how operators can customize and package samples. Nuitka compilation and encoded webhook configuration may make basic static analysis and simple hash matching less effective, but they do not make the payload invisible to behavioral detection. A different file hash is not a different criminal idea wearing a clever disguise.

The report excerpt does not identify the malware family or explain how victims receive the resulting payloads. Those details would need confirmation from the original technical analysis before attributing a campaign or naming a specific infection route.

If someone ran a suspected sample​

Treat actual execution differently from merely viewing the article or downloading an archive that was never opened.

  1. Disconnect the affected PC from the network to limit further exfiltration.
  2. From a separate trusted device, change passwords for accounts used in the affected browsers, starting with email, password managers, financial services and administrator accounts.
  3. Revoke active sessions and remove unfamiliar connected apps or devices. Changing a password does not always invalidate existing sessions.
  4. Enable MFA and verify recovery addresses, phone numbers and email forwarding rules.
  5. Replace exposed payment cards through the card issuer if card details were stored in the browser or suspicious transactions appear.
  6. Request individualized cleanup through MalwareTips’ Malware Removal Assistance team. A negative antivirus scan would not prove that credentials or cookies were never stolen.

If the report was only read and no associated file or command was downloaded and executed, these incident-response steps are not warranted merely because the malware targets the same browser installed on the PC.
 
Back
Top