TIKTOUK Toolkit Harvests AWS, SMTP, and API Credentials From Exposed WordPress Files
LevelBlue detailed TIKTOUK, a WordPress credential-harvesting toolkit of Python scripts and a Go crawler that steals SMTP, AWS, and API secrets from exposed backups and JavaScript; one report cites a leaked control panel holding ~50,000 credentials across…
LevelBlue researchers analyzed TIKTOUK, a credential-collection toolkit built from Python scripts wp2s_poll.py and wp2s_crack.py and a Go crawler, jscrawl-amd64, which takes its targets from an HTTP hub. The toolkit harvests exposed files such as wp-config.php.bak and .env, parses exposed WordPress backups, environment files, and database logs for secrets, and decrypts credentials stored by the WP Mail SMTP, Easy WP SMTP, and FluentSMTP plugins, including deriving Amazon SES passwords from AWS secrets. Its JavaScript scanner looks for SendGrid, Anthropic, Amazon Bedrock, and AWS-shaped API keys. LevelBlue linked TIKTOUK's request structures to the wp2shell chain CVE-2026-60137 and CVE-2026-63030, which can lead to unauthenticated remote code execution on WordPress versions before 6.8.6, 6.9.5, or 7.0.2, but did not demonstrate successful exploitation of these CVEs. The reports disagree on real-world impact: Cyber Security News reports a leaked TIKTOUK control panel contained roughly 50,000 real server-side credentials across about 37,000 domains, including hundreds of validated AWS keys, and that a related Go botnet with remote command execution capability was also identified; GBHackers states that LevelBlue's tests used synthetic responses and that live exploitation or stolen credentials were not confirmed. All testing described was performed by LevelBlue researchers.
- TIKTOUK comprises Python scripts wp2s_poll.py and wp2s_crack.py and a Go crawler, jscrawl-amd64, which take targets from an HTTP hub.
- The toolkit harvests exposed files such as wp-config.php.bak and .env, and parses exposed WordPress backups, environment files, and database logs for secrets.
- TIKTOUK decrypts credentials from the WP Mail SMTP, Easy WP SMTP, and FluentSMTP plugins and can derive Amazon SES passwords from AWS secrets.
- The JavaScript scanner targets SendGrid, Anthropic, Amazon Bedrock, and AWS key patterns.
- Request structures are linked to CVE-2026-60137 and CVE-2026-63030 (the wp2shell chain), which can chain to unauthenticated remote code execution on WordPress before 6.8.6, 6.9.5, or 7.0.2; successful exploitation was not demonstrated.
- Fixed WordPress releases are 6.8.6, 6.9.5, and 7.0.2.
- Cyber Security News reports a leaked control panel held ~50,000 server-side credentials across ~37,000 domains, including hundreds of validated AWS keys.
Coverage timelineoldest first · each row is one article
- · 14h agoTIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
GBHackers· 64
TIKTOUK harvests exposed WordPress files and JavaScript to steal SMTP, AWS, and API credentials.
- · 11h agoExposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Cyber Security News· 65
LevelBlue exposed the TIKTOUK toolkit harvesting ~50,000 credentials from 37,000 domains via exposed WordPress backups, including active AWS keys.
Vulnerabilities in this storyAll →
- CVE-2026-630309.810%WordPress Core Route Confusion (wp2shell) Enables SQL Injection to RCEpublished · WordPress Core KEV PoC ×4+1 related
| CVE | Vulnerability | CVSS |
|---|