Cyber Security News

TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks

A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning.

The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64.

All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and extracted data back to dedicated endpoints.

The wp2s_poll.py component begins by identifying WordPress deployments and probing REST API behavior.

It sends batch requests containing the malformed http://: path alongside a DELETE request targeting /wp/v2/categories/0 and a POST request for /wp/v2/block-renderer/core/paragraph.

Researchers observed the tool retrying the same requests using multipart encoding after JSON submissions received HTTP 403 responses.

The multipart requests then returned HTTP 200 responses, making the transition between JSON and multipart payloads a potentially useful telemetry signal for defenders investigating suspicious WordPress activity.

Beyond platform detection, the script scans returned page content for credentials and secret-like strings.

This enables the operator to pair reconnaissance with opportunistic collection of exposed tokens, access keys, and configuration values.

The more capable wp2s_crack.py component attempts to retrieve exposed files including wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log.

These paths can expose database passwords, WordPress cryptographic keys, deployment metadata, source-control remotes, debug output, and application secrets when server-side access controls are misconfigured.

A key finding is TIKTOUK’s ability to use WordPress configuration material to recover credentials saved in encrypted mail-plugin settings.

The capability does not break the underlying cryptography; instead, it abuses the fact that the required encryption keys may be available in a leaked WordPress configuration file.

Reverse engineering identified dedicated decoding routines for WP Mail SMTP, Easy WP SMTP, and FluentSMTP.

The toolkit reportedly performs XSalsa20-Poly1305 decryption for WP Mail SMTP settings, AES-256-CTR processing for Easy WP SMTP records, and AES-256-CTR recovery for FluentSMTP values using LOGGED_IN_KEY, before removing the relevant salt suffix.

This distinction is operationally significant: encrypted SMTP settings are only protective when the corresponding WordPress keys remain inaccessible.

An exposed wp-config.php file can therefore transform encrypted plugin configuration into usable plaintext email credentials.

The toolkit also derives an Amazon SES SMTP password from an AWS secret access key, potentially allowing operators to convert cloud credentials into email-delivery credentials where SES access is available.

The jscrawl-amd64 crawler expands collection beyond WordPress server files.

It retrieves pages and linked JavaScript resources, scans client-delivered scripts, and reports matches back to the operator’s hub through /v1/ingest.

LevelBlue Researchers said that, the modular toolkit can turn publicly exposed WordPress configuration data into recoverable SMTP, AWS, database, and API credentials, creating a high-impact risk for organizations with poorly secured web infrastructure.

TIKTOUK WordPress Toolkit

Observed matching patterns included SendGrid, Anthropic, Amazon Bedrock, and AWS-shaped credentials.

Client-side JavaScript should never contain long-lived secrets, yet development artifacts, embedded configuration objects, source maps, and mistakenly published environment variables remain frequent exposure paths.

The central reporting design increases the toolkit’s risk: per-target records, including recovered plaintext credentials, are sent to /api/crack/report or /v1/ingest rather than remaining on the compromised host.

TIKTOUK’s probing behavior overlaps with the recently disclosed WordPress “wp2shell” vulnerability chain.

CVE-2026-60137 affects sanitization of the author__not_in parameter in WP_Query, while CVE-2026-63030 is a REST API batch endpoint route-confusion issue that can be chained with the SQL injection flaw for unauthenticated remote code execution.

The flaws affect WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2; CVE-2026-60137 also affects the 6.8 branch before 6.8.6.

Researchers did not demonstrate successful exploitation against a live WordPress target.

Their controlled executions used synthetic responses, meaning the analysis validates component behavior rather than confirming stolen credentials or an active end-to-end intrusion.

Defenders should urgently upgrade WordPress to fixed releases 6.8.6, 6.9.5, or 7.0.2 as applicable and verify that automatic security updates remain enabled.

Organizations unable to patch immediately should restrict anonymous access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF or reverse-proxy layer.

Security teams should investigate REST batch requests containing http://:, nested author_exclude parameters, or UNION ALL SELECT expressions, especially when a JSON request is followed by a multipart retry.

They should also hunt for access attempts to backup, environment, Git, and debug files, then correlate that activity with outbound requests to /v1/ingest or /api/crack/report.

The primary defensive lesson is straightforward: exposed configuration files can defeat otherwise correctly implemented secret encryption.

WordPress operators should remove backup artifacts from web-accessible paths, block access to dotfiles and configuration backups, rotate any credentials that may have been exposed, and audit JavaScript bundles for embedded cloud, email, and AI-service keys.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

5 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

5 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

6 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

7 hours ago