A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning.
The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64.
All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and extracted data back to dedicated endpoints.
The wp2s_poll.py component begins by identifying WordPress deployments and probing REST API behavior.
It sends batch requests containing the malformed http://: path alongside a DELETE request targeting /wp/v2/categories/0 and a POST request for /wp/v2/block-renderer/core/paragraph.
Researchers observed the tool retrying the same requests using multipart encoding after JSON submissions received HTTP 403 responses.
The multipart requests then returned HTTP 200 responses, making the transition between JSON and multipart payloads a potentially useful telemetry signal for defenders investigating suspicious WordPress activity.
Beyond platform detection, the script scans returned page content for credentials and secret-like strings.
This enables the operator to pair reconnaissance with opportunistic collection of exposed tokens, access keys, and configuration values.
The more capable wp2s_crack.py component attempts to retrieve exposed files including wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log.
These paths can expose database passwords, WordPress cryptographic keys, deployment metadata, source-control remotes, debug output, and application secrets when server-side access controls are misconfigured.
A key finding is TIKTOUK’s ability to use WordPress configuration material to recover credentials saved in encrypted mail-plugin settings.
The capability does not break the underlying cryptography; instead, it abuses the fact that the required encryption keys may be available in a leaked WordPress configuration file.
Reverse engineering identified dedicated decoding routines for WP Mail SMTP, Easy WP SMTP, and FluentSMTP.
The toolkit reportedly performs XSalsa20-Poly1305 decryption for WP Mail SMTP settings, AES-256-CTR processing for Easy WP SMTP records, and AES-256-CTR recovery for FluentSMTP values using LOGGED_IN_KEY, before removing the relevant salt suffix.
This distinction is operationally significant: encrypted SMTP settings are only protective when the corresponding WordPress keys remain inaccessible.
An exposed wp-config.php file can therefore transform encrypted plugin configuration into usable plaintext email credentials.
The toolkit also derives an Amazon SES SMTP password from an AWS secret access key, potentially allowing operators to convert cloud credentials into email-delivery credentials where SES access is available.
The jscrawl-amd64 crawler expands collection beyond WordPress server files.
It retrieves pages and linked JavaScript resources, scans client-delivered scripts, and reports matches back to the operator’s hub through /v1/ingest.
LevelBlue Researchers said that, the modular toolkit can turn publicly exposed WordPress configuration data into recoverable SMTP, AWS, database, and API credentials, creating a high-impact risk for organizations with poorly secured web infrastructure.
Observed matching patterns included SendGrid, Anthropic, Amazon Bedrock, and AWS-shaped credentials.
Client-side JavaScript should never contain long-lived secrets, yet development artifacts, embedded configuration objects, source maps, and mistakenly published environment variables remain frequent exposure paths.
The central reporting design increases the toolkit’s risk: per-target records, including recovered plaintext credentials, are sent to /api/crack/report or /v1/ingest rather than remaining on the compromised host.
TIKTOUK’s probing behavior overlaps with the recently disclosed WordPress “wp2shell” vulnerability chain.
CVE-2026-60137 affects sanitization of the author__not_in parameter in WP_Query, while CVE-2026-63030 is a REST API batch endpoint route-confusion issue that can be chained with the SQL injection flaw for unauthenticated remote code execution.
The flaws affect WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2; CVE-2026-60137 also affects the 6.8 branch before 6.8.6.
Researchers did not demonstrate successful exploitation against a live WordPress target.
Their controlled executions used synthetic responses, meaning the analysis validates component behavior rather than confirming stolen credentials or an active end-to-end intrusion.
Defenders should urgently upgrade WordPress to fixed releases 6.8.6, 6.9.5, or 7.0.2 as applicable and verify that automatic security updates remain enabled.
Organizations unable to patch immediately should restrict anonymous access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF or reverse-proxy layer.
Security teams should investigate REST batch requests containing http://:, nested author_exclude parameters, or UNION ALL SELECT expressions, especially when a JSON request is followed by a multipart retry.
They should also hunt for access attempts to backup, environment, Git, and debug files, then correlate that activity with outbound requests to /v1/ingest or /api/crack/report.
The primary defensive lesson is straightforward: exposed configuration files can defeat otherwise correctly implemented secret encryption.
WordPress operators should remove backup artifacts from web-accessible paths, block access to dotfiles and configuration backups, rotate any credentials that may have been exposed, and audit JavaScript bundles for embedded cloud, email, and AI-service keys.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…