Dossier
browser credentials
Coverage of browser credentials in the Nexus archive.
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers flagged a new typosquatting campaign targeting RubyGems users using a Windows-based information stealer. This campaign steals browser credentials and crypto wallets. OpenSourceMalware discovered the threat, which is currently being tracked under the moniker StubMaker.
- New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
A new Python-based backdoor framework called DEEP#DOOR uses tunneling services to establish persistent access and steal browser and cloud credentials from compromised hosts. The attack begins with a batch script ('install_obf.bat') that disables Windows security controls and dynamically extracts sensitive data.