logo

Force Push Scanner – Hunt GitHub Dangling Commits for Leaked Secrets

ID: 744e7f7d-6d5a-5687-8609-62f8d54d6d0d

STIX ID: report--744e7f7d-6d5a-5687-8609-62f8d54d6d0d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2025-07-11

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from major Chromium- and Gecko-based browsers on Windows. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave via DLL injection into a headless Chromium process using Early Bird APC and the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red-team tool useful for assessing credential exposure and endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.