abusing-dpapi-for-credential-access
Audited by Socket on Aug 3, 2026
2 alerts found:
SecurityMalwareHigh-risk offensive red-team skill. Its capabilities are aligned with its stated purpose, and tooling provenance is mostly legitimate, but the purpose itself is credential theft/post-exploitation at scale, including browser/session hijack material and domain-wide DPAPI decryption. This is not confirmed malware, but it is a dangerous AI-agent capability and should be classified as suspicious/high-risk.
This module is a high-risk credential-access/forensic helper that enumerates Windows DPAPI master key and related credential/Vault artifacts from a mounted profile and can decrypt/triage them by invoking external DPAPI decryption tools. It accepts plaintext passwords and NTLM hashes, forwards them to subprocesses as command-line arguments, and prints captured outputs that may contain decrypted secrets or sensitive metadata. While no network exfiltration is present in this snippet, its functionality is directly aligned with credential theft/unauthorized secret recovery, making it unsuitable as a general-purpose supply-chain dependency.