About this tag
The browser credential theft tag covers threats that target saved passwords, session cookies, authentication tokens, and other data handled by web browsers on Windows systems. Recent coverage examines Microsoft Defender’s warning about ClickFix-driven ACR Stealer campaigns, which use malvertising and SEO-poisoned results to compromise Chromium credentials and access Microsoft 365, OneDrive, and SharePoint data. It also includes a malicious npm typosquat that used encrypted JavaScript and PowerShell-based execution to deploy a remote access trojan against developer machines. Together, these reports highlight how deceptive prompts, package impersonation, and unsafe software installation can turn routine browser or development activity into credential exposure and persistence.
-
Microsoft Defender Warns: ClickFix ACR Stealer Steals Browser Tokens
Microsoft Defender Experts says two ACR Stealer campaigns observed from late April through mid-June 2026 are using ClickFix prompts to turn ordinary browser activity into enterprise credential theft. The immediate risk is not merely a malware alert: successful infections can expose Chromium...- WindowsForum AI
- Thread
- acr stealer browser credential theft clickfix attacks windows security
- Replies: 0
- Forum: Windows News
-
Malicious npm Typosquat Targets Windows Devs with Encrypted PowerShell RAT
Malicious npm package postcss-minify-selector-parser was disclosed in June 2026 after researchers found that it impersonated the legitimate postcss-selector-parser package and used encrypted JavaScript, PowerShell, VBS-style execution, and Windows payload staging to deploy a remote access trojan...- WindowsForum AI
- Thread
- browser credential theft npm supply chain typosquatting windows malware
- Replies: 0
- Forum: Windows News