TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
TIKTOUK harvests exposed WordPress files and JavaScript to steal SMTP, AWS, and API credentials.
LevelBlue researchers analyzed TIKTOUK, a credential-collection toolkit built from Python scripts wp2s_poll.py and wp2s_crack.py and a Go crawler, jscrawl-amd64. The tools take targets from an HTTP hub, harvest exposed files such as wp-config.php.bak and .env, decrypt WP Mail SMTP, Easy WP SMTP, and FluentSMTP secrets, and scan JavaScript for SendGrid, Anthropic, Amazon Bedrock, and AWS-shaped keys. Its probing overlaps the wp2shell chain CVE-2026-60137 and CVE-2026-63030, which can lead to unauthenticated remote code execution on WordPress before 6.8.6, 6.9.5, or 7.0.2. Analysts used synthetic responses and did not confirm live exploitation or stolen credentials.
- Python scripts and a Go crawler report stolen data to an HTTP hub.
- Exposed wp-config.php can unlock encrypted SMTP plugin credentials.
- CVE-2026-60137 and CVE-2026-63030 can chain to unauthenticated WordPress RCE.
- Tests used synthetic responses and did not confirm live theft.
- Fixed WordPress releases are 6.8.6, 6.9.5, and 7.0.2.
Vulnerabilities mentionedAll →
- CVE-2026-630309.810%WordPress Core Route Confusion (wp2shell) Enables SQL Injection to RCEpublished · WordPress Core KEV PoC ×4+1 related
| CVE | Vulnerability | CVSS |
|---|
Full article803 words · extracted from gbhackers.com · click to collapse
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning.
The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64.
All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and extracted data back to dedicated endpoints.
The wp2s_poll.py component begins by identifying WordPress deployments and probing REST API behavior.
It sends batch requests containing the malformed http://: path alongside a DELETE request targeting /wp/v2/categories/0 and a POST request for /wp/v2/block-renderer/core/paragraph.
Researchers observed the tool retrying the same requests using multipart encoding after JSON submissions received HTTP 403 responses.
The multipart requests then returned HTTP 200 responses, making the transition between JSON and multipart payloads a potentially useful telemetry signal for defenders investigating suspicious WordPress activity.
Beyond platform detection, the script scans returned page content for credentials and secret-like strings.
This enables the operator to pair reconnaissance with opportunistic collection of exposed tokens, access keys, and configuration values.
The more capable wp2s_crack.py component attempts to retrieve exposed files including wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log.
These paths can expose database passwords, WordPress cryptographic keys, deployment metadata, source-control remotes, debug output, and application secrets when server-side access controls are misconfigured.
A key finding is TIKTOUK’s ability to use WordPress configuration material to recover credentials saved in encrypted mail-plugin settings.
The capability does not break the underlying cryptography; instead, it abuses the fact that the required encryption keys may be available in a leaked WordPress configuration file.
Reverse engineering identified dedicated decoding routines for WP Mail SMTP, Easy WP SMTP, and FluentSMTP.
The toolkit reportedly performs XSalsa20-Poly1305 decryption for WP Mail SMTP settings, AES-256-CTR processing for Easy WP SMTP records, and AES-256-CTR recovery for FluentSMTP values using LOGGED_IN_KEY, before removing the relevant salt suffix.
This distinction is operationally significant: encrypted SMTP settings are only protective when the corresponding WordPress keys remain inaccessible.
An exposed wp-config.php file can therefore transform encrypted plugin configuration into usable plaintext email credentials.
The toolkit also derives an Amazon SES SMTP password from an AWS secret access key, potentially allowing operators to convert cloud credentials into email-delivery credentials where SES access is available.
The jscrawl-amd64 crawler expands collection beyond WordPress server files.
It retrieves pages and linked JavaScript resources, scans client-delivered scripts, and reports matches back to the operator’s hub through /v1/ingest.
LevelBlue Researchers said that, the modular toolkit can turn publicly exposed WordPress configuration data into recoverable SMTP, AWS, database, and API credentials, creating a high-impact risk for organizations with poorly secured web infrastructure.
TIKTOUK WordPress Toolkit
Observed matching patterns included SendGrid, Anthropic, Amazon Bedrock, and AWS-shaped credentials.
Client-side JavaScript should never contain long-lived secrets, yet development artifacts, embedded configuration objects, source maps, and mistakenly published environment variables remain frequent exposure paths.
The central reporting design increases the toolkit’s risk: per-target records, including recovered plaintext credentials, are sent to /api/crack/report or /v1/ingest rather than remaining on the compromised host.
TIKTOUK’s probing behavior overlaps with the recently disclosed WordPress “wp2shell” vulnerability chain.
CVE-2026-60137 affects sanitization of the author__not_in parameter in WP_Query, while CVE-2026-63030 is a REST API batch endpoint route-confusion issue that can be chained with the SQL injection flaw for unauthenticated remote code execution.
The flaws affect WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2; CVE-2026-60137 also affects the 6.8 branch before 6.8.6.
Researchers did not demonstrate successful exploitation against a live WordPress target.
Their controlled executions used synthetic responses, meaning the analysis validates component behavior rather than confirming stolen credentials or an active end-to-end intrusion.
Defenders should urgently upgrade WordPress to fixed releases 6.8.6, 6.9.5, or 7.0.2 as applicable and verify that automatic security updates remain enabled.
Organizations unable to patch immediately should restrict anonymous access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF or reverse-proxy layer.
Security teams should investigate REST batch requests containing http://:, nested author_exclude parameters, or UNION ALL SELECT expressions, especially when a JSON request is followed by a multipart retry.
They should also hunt for access attempts to backup, environment, Git, and debug files, then correlate that activity with outbound requests to /v1/ingest or /api/crack/report.
The primary defensive lesson is straightforward: exposed configuration files can defeat otherwise correctly implemented secret encryption.
WordPress operators should remove backup artifacts from web-accessible paths, block access to dotfiles and configuration backups, rotate any credentials that may have been exposed, and audit JavaScript bundles for embedded cloud, email, and AI-service keys.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.