New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
K7 Labs details a Python infostealer MaaS builder harvesting credentials, cards and session cookies from 17 Chromium browsers plus Firefox.
K7 Labs identified a Python-based infostealer distributed via a 'TokenGrabber Builder' malware-as-a-service framework that generates customized Windows payloads compiled with Nuitka or PyInstaller and exfiltrates to attacker-configured Discord or Telegram webhooks (XOR 0x5A + Base64 obfuscated). The stealer harvests credentials, payment-card data, browsing history and session cookies from 17 Chromium-based browsers plus Firefox, decrypting master keys via Windows DPAPI and AES-256-GCM. It also extracts Wi-Fi keys, Discord tokens and Roblox session cookies, persists via a Registry Run key and ONLOGON scheduled task, and includes anti-analysis checks before exfiltrating a StolenData zip via HTTP POST.
- MaaS builder compiles Python stealer to Windows binaries via Nuitka/PyInstaller for low-skilled affiliates.
- Steals credentials, cards, history and cookies from 17 Chromium browsers plus Firefox via DPAPI/AES-256-GCM decryption.
- Obfuscated Discord/Telegram webhook exfiltration plus Wi-Fi, Discord and Roblox token theft.
- Persists via HKCU Run key (WindowsUpdate) and ONLOGON scheduled task.
- Hunting signals: suspicious pip.exe execution, browser DB access, netsh wlan profile enumeration.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 429ed63ab3fbda8d22d0ac750ecfe8cc | 0c65a3f8e88559f89ed90ea9ee5c Password-Stealer ( 006dba241 ) 429ed63ab3fbda8d22d0ac750ecfe8cc Password-Stealer ( 006dba241 ) 9ffe0e45c7a3f20e4481206c1c3b |
| md5 | 610f0c65a3f8e88559f89ed90ea9ee5c | ed compromise. Indicators of Compromise Hash Detection Name 610f0c65a3f8e88559f89ed90ea9ee5c Password-Stealer ( 006dba241 ) 429ed63ab3fbda8d22d0ac750ecf |
| md5 | 9ffe0e45c7a3f20e4481206c1c3b0854 | d63ab3fbda8d22d0ac750ecfe8cc Password-Stealer ( 006dba241 ) 9ffe0e45c7a3f20e4481206c1c3b0854 Trojan ( 006e632e1 ) Note: IP addresses and domains are int |
Full article745 words · extracted from gbhackers.com · click to collapse
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies.
The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook.
The archive included a “TokenGrabber Builder” folder containing a Python builder and an embedded stealer payload.
The structure points to a malware-as-a-service (MaaS) model, allowing multiple affiliates or low-skilled operators to build and deploy individualized samples.
The builder can compile the embedded Python payload into Windows executables using Nuitka or PyInstaller, or save it as a raw Python script.
Nuitka is especially notable because it converts Python code into native binaries, reducing the presence of recoverable Python bytecode and complicating analysis with common Python decompilers.
Before compilation, the operator supplies a Discord or Telegram webhook address. The builder XOR-encrypts the address with key 0x5A, Base64-encodes it and injects it into the payload.
This approach prevents the webhook from appearing in plaintext and causes separately built samples to carry different encoded configuration values and potentially distinct hashes, weakening simple indicator-based clustering.
The builder also automatically installs dependencies when needed and searches for locally installed Python interpreters through environment paths, common installation directories and Windows Registry locations.

Unexpected pip.exe execution from non-development applications could therefore provide defenders with an early behavioral detection signal.
K7 Labs identified the Python campaign, after examining a suspicious RAR archive, “my new program called 2.rar,” which contained a nested archive named TokenGrabberBuilder.zip.
Python Infostealer Campaign
The embedded stealer checks known browser-profile paths in %LOCALAPPDATA% and %APPDATA% to target 17 Chromium-based browsers.

It collects credentials from Login Data, history from History, payment-card records from Web Data, and session material from Cookies or Network/Cookies.
To access Chromium-protected data, the malware retrieves the browser’s encrypted master key from the Local State file and attempts to decrypt it using Windows DPAPI.
It copies locked SQLite databases to a temporary location before reading them, then decrypts newer Chrome-format entries protected with AES-256-GCM or falls back to older DPAPI-based methods.
Firefox is also in scope. The stealer searches Firefox profile directories for places.sqlite and cookies.sqlite, enabling collection of browsing history and session cookies.
Session theft is particularly damaging because a valid cookie can let an attacker hijack an authenticated web session without knowing the victim’s password.
Beyond browser data, the malware enumerates saved Wi-Fi profiles through netsh wlan show profiles and attempts to extract cleartext Wi-Fi keys.
It scans Discord LevelDB storage for tokens, validates potential tokens against Discord’s API, and seeks .ROBLOSECURITY cookies that could expose Roblox accounts.
The malware establishes persistence through two methods: a Registry Run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run, using the misleading value name WindowsUpdate, and an ONLOGON scheduled task.
It further attempts to evade analysis by checking for attached debuggers, virtual-machine processes, low-capacity disks and sandbox time limits.

Collected information, including public IP address, location details, username and computer name, is assembled in memory as StolenData_<USERNAME>.zip.
The archive is then transmitted via HTTP POST to the attacker-controlled webhook, limiting artifacts that might otherwise be visible through disk-based monitoring.
Organizations should prioritize behavior-based detection rather than relying only on static file signatures.
Useful hunting signals include suspicious child execution of pip.exe, browser database access by untrusted processes, netsh commands requesting Wi-Fi profiles, creation of Run-key persistence or login-triggered scheduled tasks, and outbound POST requests to unfamiliar webhook infrastructure.
The campaign also underscores the risk posed by archive-delivered malware.
Users should avoid executing files extracted from unsolicited or unverified archives, while defenders should enforce multifactor authentication, monitor anomalous session activity and rapidly revoke browser sessions or reset credentials following a suspected compromise.
Indicators of Compromise
| Hash | Detection Name |
| 610f0c65a3f8e88559f89ed90ea9ee5c | Password-Stealer ( 006dba241 ) |
| 429ed63ab3fbda8d22d0ac750ecfe8cc | Password-Stealer ( 006dba241 ) |
| 9ffe0e45c7a3f20e4481206c1c3b0854 | Trojan ( 006e632e1 ) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.