Python MaaS Infostealer Builder Creates Versatile Credential Theft Tools
A new Python-based malware builder, dubbed Python MaaS Infostealer, allows attackers to easily create custom infostealer executables targeting credentials from 17 browsers and Firefox.

A sophisticated Python-based malware builder, identified as Python MaaS Infostealer, is enabling threat actors to generate versatile Windows executables designed for credential theft. This "malware-as-a-service" (MaaS) tool allows operators to compile a core infostealer payload into distinct Windows programs, capable of targeting sensitive data across a wide array of browsers and applications.
The infostealer's primary function is to pilfer saved passwords, credit card details, session cookies, messaging tokens, and Wi-Fi passwords. It achieves this by targeting 17 different Chromium-based browsers, as well as Mozilla Firefox. The stolen information is then exfiltrated to an attacker-controlled webhook, configured by the operator during the build process. This modular approach allows for frequent changes to the payload, making signature-based detection more challenging.
Researchers at K7 Security Labs discovered the tool packaged within nested archives. The builder itself offers flexibility, allowing operators to compile the embedded Python stealer into a Windows executable using tools like Nuitka or PyInstaller, or to distribute it as a raw script. This adaptability means the same underlying code can manifest in various forms, complicating threat analysis.
Beyond browser data, the infostealer also targets Discord tokens and Roblox session cookies, recognizing their value for account takeover. It further expands its scope by harvesting saved Wi-Fi profiles, effectively gathering network credentials. The payload also collects system information, including the victim's public IP address, approximate location, time zone, Windows username, and computer name, compiling this data into an in-memory archive before transmission.
To evade detection, the Python MaaS Infostealer incorporates several anti-analysis techniques. It performs checks for debuggers and virtual machines, exits if the system has less than 50 GB of disk space, and varies its sleep times to mimic legitimate activity. It also employs delayed loading of libraries. For persistence, the malware establishes a Windows startup registry entry and creates a scheduled task that runs upon user logon, ensuring its continued operation even after a system restart.
The builder itself automates dependency installation and stores the configured webhook address, which is then encoded using XOR and Base64 to obscure it from simple string searches within the compiled binary. This obfuscation adds another layer of difficulty for security analysts attempting to identify the exfiltration endpoint.
The immediate risk posed by this toolchain is significant, as stolen session cookies can grant attackers access to active accounts without needing passwords, and compromised payment or Wi-Fi credentials can lead to further financial loss and network intrusion. The ability to easily generate new, varied builds of the infostealer makes it a persistent threat in the credential theft landscape.
K7 Security Labs recommends vigilance against unusual Python package installations, unexpected startup entries or scheduled tasks, unauthorized access to browser credential stores, and outbound network connections to unfamiliar webhooks. Users should exercise caution when opening downloaded files, and security teams should analyze these behaviors collectively rather than relying solely on file hashes, given the builder's capacity for generating unique variants.