A Python-based infostealer builder that enables threat actors to generate customized Windows payloads capable of stealing browser credentials, payment-card data, session cookies, Discord tokens, Wi-Fi passwords and extensive system information.
Rather than functioning as a single-use stealer, the package includes a builder interface and an embedded payload, providing a model consistent with Malware-as-a-Service operations.
Operators can configure an attacker-controlled webhook, choose a compilation method and generate separate Windows binaries for distribution.
This design can help affiliates deploy samples with distinct hashes and exfiltration infrastructure, complicating correlation and signature-based detections.
The builder automatically installs required Python dependencies when launched, reducing setup requirements for criminals operating in clean Python environments.
That behavior makes unexpected pip.exe activity from non-development applications a potentially useful detection signal.
The payload reverses this process at runtime, preventing the webhook from appearing as plaintext within the compiled executable.
Operators can build payloads with Nuitka, PyInstaller or save the malware as a raw Python script.
Nuitka is particularly notable because it compiles Python code through C into a native executable, limiting the usefulness of Python-bytecode recovery tools.
The builder reportedly advertises this route as offering stronger antivirus evasion, while PyInstaller produces a package that can often be unpacked to recover .pyc bytecode.
The builder also excludes non-essential Python libraries such as tkinter, matplotlib, numpy and pandas to reduce file size and potentially minimize its detection footprint.
K7 Security Labs said in a report shared with GBhackers, the malware was found inside a suspicious nested archive chain, beginning with a RAR file named “my new program called 2.rar” and a ZIP archive called “TokenGrabberBuilder.zip.”
The embedded payload, tracked as stealer.py, is designed for Windows and targets at least 17 Chromium-based browsers.
The interface stores the selected webhook address in a local webhook.txt file, then embeds the destination into the generated stealer. Before insertion, the URL is XOR-encrypted with the 0x5A key and Base64-encoded.
It accesses browser databases including Login Data, History, Web Data and Cookies to collect saved usernames, passwords, browsing activity, stored payment-card details and session cookies.
To decrypt protected Chromium credentials, the malware obtains the browser’s encrypted master key from the Local State file and uses Windows DPAPI, followed by AES-GCM decryption where applicable.
Firefox is also targeted through profile directories under %APPDATA%\Mozilla\Firefox\Profiles.
The stealer reads places.sqlite for browsing history and cookies.sqlite for session cookies, which can expose authenticated web sessions even where a password is not directly stolen.
The malware additionally runs netsh wlan show profiles and uses the key=clear option to retrieve saved Wi-Fi credentials in plaintext.
It searches Discord LevelDB storage for tokens, validates potentially active tokens through Discord’s API, and hunts for .ROBLOSECURITY cookies that could enable unauthorized access to Roblox accounts.
To frustrate analysis, the stealer stores sensitive strings as Base64-encoded data encrypted with XOR. It dynamically loads higher-risk modules only when needed and checks for debuggers through the Windows IsDebuggerPresent() API.
It also terminates when it detects virtualization-related processes, identifies a disk smaller than 50 GB or encounters sandbox-like execution conditions.
For persistence, the malware writes a deceptive WindowsUpdate entry to HKCU\Software\Microsoft\Windows\CurrentVersion\Run and creates an ONLOGON scheduled task.
The dual method gives the payload multiple opportunities to relaunch after reboot or user sign-in.
Collected data is compressed into an in-memory archive named StolenData_<USERNAME>.zip, limiting artifacts left on disk.
The archive can include public IP information, country, city, ISP, coordinates, timezone, username and hostname alongside stolen browser and wireless data.
It is then sent through an HTTP POST request to the operator’s configured webhook.
Defenders should watch for suspicious access to browser credential stores, unusual netsh Wi-Fi-profile queries, unexpected Run-key modifications, newly created scheduled tasks, anomalous pip.exe execution and outbound uploads to untrusted webhook services.
Because each build can carry different configuration data and hashes, behavioral detections are likely to be more reliable than static indicators alone.
| Hash | Detection Name |
| 610f0c65a3f8e88559f89ed90ea9ee5c | Password-Stealer ( 006dba241 ) |
| 429ed63ab3fbda8d22d0ac750ecfe8cc | Password-Stealer ( 006dba241 ) |
| 9ffe0e45c7a3f20e4481206c1c3b0854 | Trojan ( 006e632e1 ) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…