logo

GitPhish – OAuth Device Code Phishing for GitHub Repos, Secrets, and CI/CD

ID: 0d353190-5fda-5a05-8427-3f07176d2e0b

STIX ID: report--0d353190-5fda-5a05-8427-3f07176d2e0b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-06-20

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post‑exploitation credential-harvesting tool (Windows executable + DLL) that targets Chromium- and Gecko-based browsers to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave via spawning a headless Chromium process, injecting a DLL with Early Bird APC to access the IElevator COM interface, and decrypts browser vaults locally; Opera/Vivaldi and Firefox are handled via DPAPI or NSS methods. The report covers extraction output, evasion features, operational usage, detection opportunities, and mitigation advice for red-team and defensive testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.