Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers
K7 Labs analyzed a Python malware-as-a-service builder that steals browser passwords, cards, and cookies from 17 Chromium browsers.
K7 Security Labs analyzed a nested archive holding a Python malware-as-a-service builder, TokenGrabber, that can compile an infostealer with Nuitka or PyInstaller or leave it as a script. The payload steals saved passwords, payment cards, history, and cookies from 17 Chromium-based browsers, plus Firefox history and cookies, and also collects Discord tokens, Roblox session cookies, Wi-Fi passwords, and host and location details. Stolen data is built into an in-memory archive and sent to an operator webhook whose address is XOR- and Base64-encoded. The stealer checks for debuggers and virtual machines, exits on disks under 50 GB, and persists through a Run key named WindowsUpdate and a logon scheduled task. K7 did not establish how it is delivered or how many machines were infected.
- Operators can ship the Python stealer as a script or a Windows executable.
- It reads passwords, cards, history, and cookies from 17 Chromium browsers.
- Discord tokens, Roblox cookies, Wi-Fi passwords, and system details are collected.
- Data is archived in memory and posted to an operator-configured webhook.
- Persistence uses a deceptive Run key and a logon scheduled task.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 429ed63ab3fbda8d22d0ac750ecfe8cc | 89ed90ea9ee5c Listed as Password-Stealer ( 006dba241 ). MD5 429ed63ab3fbda8d22d0ac750ecfe8cc Listed as Password-Stealer ( 006dba241 ). MD5 9ffe0e45c7a3f |
| md5 | 610f0c65a3f8e88559f89ed90ea9ee5c | on stealer sample identified through a VirusTotal link. MD5 610f0c65a3f8e88559f89ed90ea9ee5c Listed as Password-Stealer ( 006dba241 ). MD5 429ed63ab3fbd |
| md5 | 9ffe0e45c7a3f20e4481206c1c3b0854 | 0ac750ecfe8cc Listed as Password-Stealer ( 006dba241 ). MD5 9ffe0e45c7a3f20e4481206c1c3b0854 Listed as Trojan ( 006e632e1 ). File name my new program ca |
| sha256 | 1ab7846f93678fb727c95df133c1b0a050760b11dd164ca5f6408e84398b676e | s of compromise (IoCs):- Type Indicator Description SHA-256 1ab7846f93678fb727c95df133c1b0a050760b11dd164ca5f6408e84398b676e Archive examined by the researchers, identified through a V |
| sha256 | 7053dc55b4ba193ea162f01a329427fd244d8163a65cbf2a7f86c04c849c8114 | researchers, identified through a VirusTotal link. SHA-256 7053dc55b4ba193ea162f01a329427fd244d8163a65cbf2a7f86c04c849c8114 Nested builder archive identified through a VirusTotal link |
Full article1,038 words · extracted from cybersecuritynews.com · click to collapse
A Python-based malware builder can turn a single stealer into Windows programs for different operators. The tool packages a payload designed to take saved passwords, payment card details and browser cookies, then send them to an attacker-controlled webhook set by its operator.
Its reach extends beyond browsers to messaging accounts, wireless passwords and details about the infected computer. The sample reached researchers inside a compressed archive containing another archive with the builder.
This shows its packaging, but the report does not establish how victims receive it or how many machines were infected.
Its builder-and-payload design resembles other malware-as-a-service credential theft operations that let users produce separate builds. Analysts at K7 Security Labs identified the two-part tool while examining the nested package.
K7 Security Labs said in a report shared with Cyber Security News (CSN) that operators can compile the embedded Python stealer into a Windows executable using Nuitka or PyInstaller, or leave it as a script. This flexibility could make the same code appear in different forms.
.webp)
The immediate risk is not limited to exposed passwords. Stolen session cookies may let an intruder use an account that is already signed in, even without knowing its password, while payment details and wireless passwords widen the damage. As infostealer logs fuel compromises, one infected machine can affect more than its owner.
Python MaaS Infostealer Builder
The payload checks user data folders for 17 Chromium-based browsers and reads saved login details, browsing history, payment card entries and session cookies.
It copies browser databases to a temporary location when locked, then uses Windows data-protection functions and browser encryption keys to recover stored secrets. This is a Windows threat, not a browser exploit.
Firefox is also in scope, but separately from those 17 browsers. The stealer reads Firefox history and cookie records, while Chromium routines also target passwords and cards.
Similar breadth appears in other browser-focused stealer investigations, but the number 17 in this case refers specifically to Chromium-based browsers. The malware searches for Discord tokens, checks whether they still work and collects Roblox session cookies.
.webp)
These items can be valuable because an active session may offer access without requiring a fresh password. It searches saved Wi-Fi profiles for their passwords too, adding network credentials to the stolen browser and account data.
Location and system details round out the collection. The payload records the victim’s public IP address, approximate location, time zone, Windows user name and computer name.
It then builds an archive in memory and sends it through a configured webhook. This leaves less file-system evidence than writing an archive to disk before upload.
Builder Evasion and Detection
The builder installs missing Python dependencies automatically and stores its chosen webhook for later build sessions.
It encodes that address using XOR and Base64 before insertion into the payload, so a simple search for the plain address in a compiled program may fail. Operators can choose between two executable-building methods or keep a raw script for changes.
Once launched, the stealer tries to avoid examination. It checks for a debugger, looks for signs of virtual machines, exits on systems with less than 50 GB of disk space and varies its sleep time.
It also delays loading some libraries until they are needed. These checks may hinder short automated tests without changing what it steals.
To return after a restart, the payload uses both a Windows startup registry entry and a scheduled task that runs at logon. This gives it another chance if one is removed.
.webp)
Like Python stealer targeting Discord, it also treats account tokens as data worth checking before sending to the operator.
K7 recommends watching for unusual Python package installation, unexpected startup entries or scheduled tasks, access to browser credential stores and outbound posts to unfamiliar webhooks.
Users should double-check downloaded files before opening them and keep security protections current. Defenders should judge these behaviors together rather than rely on hashes, since individual builds can vary when operators change their settings for each build.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 1ab7846f93678fb727c95df133c1b0a050760b11dd164ca5f6408e84398b676e | Archive examined by the researchers, identified through a VirusTotal link. |
| SHA-256 | 7053dc55b4ba193ea162f01a329427fd244d8163a65cbf2a7f86c04c849c8114 | Nested builder archive identified through a VirusTotal link. |
| SHA-256 | 9e471343255259f7fb388f1f07b0e023261630dbdc01f5d647dc99f452119eff | Python stealer sample identified through a VirusTotal link. |
| MD5 | 610f0c65a3f8e88559f89ed90ea9ee5c | Listed as Password-Stealer ( 006dba241 ). |
| MD5 | 429ed63ab3fbda8d22d0ac750ecfe8cc | Listed as Password-Stealer ( 006dba241 ). |
| MD5 | 9ffe0e45c7a3f20e4481206c1c3b0854 | Listed as Trojan ( 006e632e1 ). |
| File name | my new program called 2.rar | Outer archive examined by the researchers. |
| File name | TokenGrabberBuilder.zip | Nested archive containing the builder. |
| Folder name | TokenGrabber Builder | Folder inside the nested archive. |
| File name | stealer.py | Python stealer script. |
| File name | webhook.txt | Builder file used to retain a configured webhook address. |
| Archive name pattern | StolenData_<USERNAME>.zip | Name assigned to the stolen-data archive assembled in memory. |
| Registry value | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | Autorun location and deceptive value name used for persistence. |
| URL | https://pastebin.com/api/api_post.php | Legitimate service API address shown in the malware’s decoded strings as a secondary exfiltration endpoint; not a unique attacker-controlled URL. |
| Target file | Local State | Chromium browser file accessed for encryption-key material. |
| Target file | Login Data | Chromium database targeted for saved logins. |
| Target file | History | Chromium database targeted for browsing history. |
| Target file | Web Data | Chromium database targeted for payment card details. |
| Target file | Cookies | Chromium cookie database targeted for sessions. |
| Target file | Network/Cookies | Alternate Chromium cookie database location. |
| Target file | places.sqlite | Firefox history database targeted by the stealer. |
| Target file | cookies.sqlite | Firefox cookie database targeted by the stealer. |
| Process name | pip.exe | Unexpected execution by a non-development application is a behavioral clue, not evidence of infection on its own. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.