T1528Steal Application Access Token
T1528 — Steal Application Access Token is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 34 detection use cases covering it and 82 threat-intel articles citing it.
Credential Access
34Use cases
82Articles
0Sub-techniques
1Tactic
Use cases covering this technique (34)
OAuth consent / suspicious app grant [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Azure AD Device Code Authentication Azure AD OAuth Application Consent Granted By User Azure AD User Consent Blocked for Risky Application Azure AD User Consent Denied for OAuth Application O365 File Permissioned Application Consent Granted by User O365 Mail Permissioned Application Consent Granted by User O365 User Consent Blocked for Risky Application O365 User Consent Denied for OAuth Application [LLM] OAuth consent grant to unfamiliar third-party AI / SaaS app — Vercel-style trust chain attack [LLM] npm install-time process reads .npmrc, SSH key, or cloud-credential file [LLM] Meta Graph API request with access_token in URL query string (CVE-2026-48039 leak signature) [LLM] Cloud/SSH/npm credential file access by Node or Bun during npm install [LLM] Cloud IMDS credential harvesting from node/bun process on CI runner [LLM] Cloud credential file access by node/python runtime [LLM] Kubernetes API curl/wget with ServiceAccount token from container [LLM] Cloud metadata service hit (IMDSv2 / ECS) from node process under node_modules [LLM] Shai-Hulud npm postinstall reads cloud credential files (~/.aws, ~/.ssh, ~/.kube, gcloud ADC) [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) [LLM] Package-manager process harvesting cloud metadata / Vault (IMDS 169.254.169.254, ECS 169.254.170.2, Vault :8200) [LLM] UTA0355 device-code phishing: deviceCode auth flow with cross-IP token redemption [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) [LLM] Coder CVE-2026-46354 - Agent token redemption: PKCS#7 POST followed by gitsshkey / external-auth GET [LLM] Context.ai compromised Chrome extension installed on host (ID omddlmnhcofjbnbflmjginpjjblphbgk) [LLM] First-time OAuth consent granting Drive/Mail read scope to non-sanctioned third-party app [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot)Articles citing this technique (82)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit [GHSA / CRITICAL] GHSA-jpvj-wpmj-h7rv: Supply chain compromise via malicious @cap-js/openapi art-123
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-159
crit The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-248
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-254
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-348
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-352