DANGER
malware detected
github.com / itzzkirito
itzzkirito/ Token-Grabber
Python·12 files·commit 2db22b6·scanned 3d ago·cached ✓
70/100
DANGEROUS
Sensitive capability combinations reachable from entry points. Do not run without review.
This repository contains patterns associated with malware. Do NOT run this code.
verdict accurate?
Crypto/Web3 project
Research / educational context
threat-state: dangerouslive
FINDINGS ░▒▓
criticalBrowser credential store accessAccessing Chrome, Firefox, Edge, or Brave profile directories to steal cookies, passwords, and session tokens.DemonZ.py
'Lightcord': ROAMING + '\\Lightcord',
'Brave': LOCAL + '\\BraveSoftware\\Brave-Browser\\User Data',
'Chrome': LOCAL + '\\Google\\Chrome\\User Data',
'Chrome SxS': LOCAL + '\\Google\...+10warningHigh-entropy string literalsFound 9 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.DemonZ.py+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
7 files scanned @ 2db22b6 | 8/21/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access10
obfuscation3
supply chain6
owasp / injection0
telemetry
files 7/12rules hit 6engine v5commit 2db22b6
github
itzzkirito/Token-Grabber
Advanced Discord token recovery framework for Windows. Extracts tokens from 20+ Chromium browsers, Firefox, and Discord clients via AES-GCM/DPAPI decryption. Features parallel validation, webhook delivery with fallback, stealth mode, custom EXE icon builds, and full JSON configuration.
1
4
191d
12 files
7 scanned(58%)
2db22b6
architecture░▒▓
entry (0) flagged (1) pkg (18)
21 nodes · 22 edgesscroll to zoom · click node to jump to finding