T1555.003Credentials from Web Browsers
T1555.003 — Credentials from Web Browsers is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 24 detection use cases covering it and 175 threat-intel articles citing it.
Credential Access
24Use cases
175Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1555 · Credentials from Password Stores
Use cases covering this technique (24)
Infostealer — non-browser process accessing browser cookie/login DBs [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Non Chrome Process Accessing Chrome Default Dir Non Firefox Process Access Firefox Profile Dir Possible Browser Pass View Parameter Windows Credentials from Password Stores Chrome Copied in TEMP Dir Windows Credentials from Web Browsers Saved in TEMP Folder [LLM] Suspicious ProcessAccess to chrome.exe / msedge.exe with injection-grade rights [LLM] macOS browser 'Safe Storage' master-key theft via security find-generic-password [LLM] Non-Chrome process accessing Google Chrome synced-passkey LevelDB store [LLM] Command line referencing Chrome Sync Data LevelDB passkey path (copy/stage for exfil) [LLM] Browser credential-store theft via OctLurk browser password decryptor [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions [LLM] Mastra easy-day-js second-stage stealer payload by SHA256 [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writes [LLM] Non-browser process reading Chrome/Edge/Opera Login Data or Local State [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2)Articles citing this technique (175)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. art-35
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning art-69
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices art-85
crit Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo art-86
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88
high Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets art-90
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials art-193
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-324
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-364
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-426
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-458
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-468
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-477
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-486
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-499
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-520
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-596
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1506
high Preventing XSS in Django art-1837
med You should be using HTTP Strict Transport Security (HSTS) headers in your Node.js server art-1897
crit XSS Attacks: The Next Wave art-3664