T1555.003Credentials from Web Browsers
T1555.003 — Credentials from Web Browsers is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 22 detection use cases covering it and 146 threat-intel articles citing it.
Credential Access
22Use cases
146Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1555 · Credentials from Password Stores
Use cases covering this technique (22)
Infostealer — non-browser process accessing browser cookie/login DBs [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Non Chrome Process Accessing Chrome Default Dir Non Firefox Process Access Firefox Profile Dir Possible Browser Pass View Parameter Windows Credentials from Password Stores Chrome Copied in TEMP Dir Windows Credentials from Web Browsers Saved in TEMP Folder [LLM] Node.js spawning Python credential-stealer child [LLM] ChromEggscalator: Chromium launched with --remote-debugging-port for cookie/credential theft [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions [LLM] Mastra easy-day-js second-stage stealer payload by SHA256 [LLM] Non-browser process copying Chrome/Edge/Brave Login Data, Web Data, or wallet extension LevelDB state [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writes [LLM] Non-browser process reading Chrome/Edge/Opera Login Data or Local State [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2)Articles citing this technique (146)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Begun, the Patch Wars have art-150
crit ESET Threat Report H1 2026 art-221
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-253
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-380
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-454
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1483
high Preventing XSS in Django art-1814
med You should be using HTTP Strict Transport Security (HSTS) headers in your Node.js server art-1874
crit XSS Attacks: The Next Wave art-3641