Weaponizing Dependabot – Exploiting GitHub Automation for Supply Chain Attacks
ID: af9df003-46b4-5619-9f50-b1f1b1df1b62
STIX ID: report--af9df003-46b4-5619-9f50-b1f1b1df1b62
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation credential-harvesting tool that targets major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox) to extract passwords, cookies, OAuth refresh tokens, credit cards, autofill data, and browsing history. It bypasses App-Bound Encryption in Chromium-based browsers by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface to decrypt keys, uses DPAPI for some browsers, and directly handles Firefox NSS decryption; the tool includes operational evasion features and writes structured JSON output for red team or offensive use, with guidance on detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
