Malware Infections (Infostealers)
Overview
Malware infection data comes from information-stealing malware (infostealers) that capture sensitive data from infected devices and transmit it to threat actors. This data offers unique insights into compromised credentials, cookies, system information, and leaked secrets that may not appear in traditional database breaches.
Characteristics
- Origin: Data captured by malware from infected user devices.
- Freshness: Often more recent than database breaches, representing active compromise.
- Comprehensiveness: Can include data from multiple services accessed on the infected device, system details, and potentially sensitive files or source code.
- Context: May include system information and behavioral data in addition to credentials and secrets.
Infostealer Types
Our system monitors data from 55+ different infostealer types, including:
- RedLine
- Meta
- LummaC2
- Vidar
- Azorult
- Raccoon
- Cryptbot
- And many more
Data Categories from Malware
Infostealers typically collect multiple types of sensitive information from infected devices:
Credentials
Stolen login information including:
- Source application (browser or email client)
- Website or service URL
- Username/email
- Plaintext password
Cookies
Browser cookies that can enable session hijacking:
- Source browser
- Website domain
- Expiry details
- Cookie values
Leaked Secrets
Hardcoded secrets found within files, configuration, or environment variables on the infected machine. These are often critical for accessing services and infrastructure:
- Detection: We utilize specialized tools like Gitleaks, configured with a comprehensive set of rules, to scan files collected by infostealers. These rules are designed to identify patterns characteristic of various secret types.
- Validation: Potential secrets undergo validation steps to reduce false positives and confirm the likelihood of a valid secret.
- Types Detected: Common examples include API Keys & Tokens (AWS, GCP, Azure, GitHub, Slack, Stripe, Twilio, etc.), Private Keys (SSH, PGP), Database Credentials, Service Account Tokens (e.g., GCP, Vault), OAuth Tokens, and Configuration Secrets (e.g., Kubernetes secrets in YAML).
Detected Secret Types
The tables below list every secret type our system can currently detect within malware logs, grouped by the kind of service the credential unlocks. Each rule ID is the exact value returned in the type field of the secret array, and the exact value accepted by the type path parameter of the secrets endpoints.
The authoritative, always-current list is the type parameter of the secrets endpoints in the Dark Web API specification. New rule IDs appear there as detection rules ship, so check the specification if a type you expect is not listed here.
The Example Format column shows the shape a token takes, not a real value. Literal characters that a secret must contain are shown as-is, while variable characters are masked:
****— a run of characters whose length is fixed by the pattern.<N chars>— the same, where the run is too long to draw.<N-M chars>— a run whose length varies between N and M.<N+ chars>— a run of at least N characters, with no upper bound.<description>— a structural element such as a hostname, username, or file name.
AI, machine learning & search
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
anthropic-admin-api-key | Anthropic admin API key | sk-ant-admin01-<93 chars>AA |
anthropic-api-key | Anthropic API key | sk-ant-api03-<93 chars>AA |
assemblyai-api-key | AssemblyAI API key | ******************************** |
aws-amazon-bedrock-api-key-long-lived | Amazon Bedrock long-lived API key | ABSK<109-269 chars> |
aws-amazon-bedrock-api-key-short-lived | Amazon Bedrock short-lived API key | bedrock-api-key-YmVkcm9jay5hbWF6b25hd3MuY29t |
brave-search-api-key | Brave Search API key | BSA<24-40 chars> |
cerebras-api-key | Cerebras API key | csk-<48 chars> |
cohere-api-token | Cohere API Token | **************************************** |
cursor-api-key | Cursor API key | key_<64 chars> |
deepgram-api-key | Deepgram API key | **************************************** |
deepseek-api-key | DeepSeek API key | sk-******************************** |
devin-personal-api-key | Devin personal API key | apk_user_<120-180 chars> |
devin-service-api-key | Devin service API key | apk_<80-100 chars> |
devin-service-user-token | Devin service user token | cog_<52 chars> |
elevenlabs-api-key | ElevenLabs API key | sk_<48 chars> |
gcp-gemini-api | Google Gemini API key | AQ.Ab8RN6<44 chars> |
greptile-api-key | Greptile API key | <48 chars> |
groq-api-key | Groq API key | gsk_<52 chars> |
huggingface-access-token | Hugging Face Access token | hf_********************************** |
huggingface-organization-api-token | Hugging Face Organization API token | api_org_********************************** |
kagi-api-key | Kagi API key | ***********.<43 chars> |
kimi-api-key | Kimi API key | sk-<48 chars> |
langchain-langsmith-personal-access-token | LangSmith personal access token | lsv2_pt_********************************_********** |
langchain-langsmith-service-key | LangSmith service key | lsv2_sk_********************************_********** |
lighton-paradigm-api-key | LightOn Paradigm API key | <40-80 chars> |
minimax-api-key | MiniMax API key | sk-api-<119 chars> |
mistral-api-key | Mistral AI API key | ******************************** |
nexos-ai-user-api-key | nexos.ai user API key | nexos-<128 chars> |
nvidia-api-key | NVIDIA API key | nvapi-<60-70 chars> |
ollama-api-key | Ollama API key | ********************************.************************ |
openai-api-key | OpenAI API Key | sk-proj-<74 chars>T3BlbkFJ<74 chars> |
openrouter-api-key | OpenRouter API key | sk-or-v1-<64 chars> |
perplexity-api-key | Perplexity API key | pplx-<48 chars> |
pinecone-api-key | Pinecone API key | pcsk_<5-6 chars>_<63 chars> |
privateai-api-token | PrivateAI API Token | ******************************** |
replicate-api-token | Replicate API token | r8_************************************* |
runpod-api-key | RunPod API key | rpa_<46 chars> |
stability-ai-api-key | Stability AI API key | sk-<48 chars> |
togetherai-api-key | Together AI API key | tgp_v1_<43 chars> |
upstage-api-key | Upstage API key | <40-50 chars> |
vercel-ai-gateway-key | Vercel AI Gateway key | vck_<56 chars> |
weights-and-biases-api-key | Weights & Biases API key | **************************************** |
weights-and-biases-api-key-v1 | Weights & Biases API key (v1 format) | wandb_v1_<77 chars> |
xai-api-key | xAI API key | xai-<70-120 chars> |
zai-api-key | Z.ai API key | ********************************.**************** |
Cloud providers & infrastructure
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
alibaba-access-key-id | Alibaba Cloud AccessKey ID | LTAI<17-21 chars> |
alibaba-secret-key | Alibaba Cloud Secret Key | ****************************** |
alibaba-sts-access-key-id | Alibaba Cloud STS access key ID | STS.<16-64 chars> |
alibaba-sts-access-key-secret | Alibaba Cloud STS access key secret | <30-64 chars> |
alibaba-sts-security-token | Alibaba Cloud STS security token | CAIS<20-1024 chars> |
aws-access-token | AWS Access Key ID | AKIA**************** |
aws-secret-key | AWS Secret Key | **************************************** |
azure-ad-client-secret | Azure AD Client Secret | ****Q~<31-34 chars> |
azure-app-configuration-connection-string | Azure app configuration connection string | Endpoint=https://<store>.azconfig.io;Id=<id>;Secret=<36-100 chars> |
azure-client-id | Azure client ID | Not currently detected — see note below |
azure-servicebus-connection-string | Azure Service Bus connection string | Endpoint=sb://<namespace>.servicebus.windows.net/;SharedAccessKeyName=<name>;SharedAccessKey=<32-100 chars> |
azure-storage-account-key | Azure storage account key | <86 chars>== |
azure-storage-account-name | Azure storage account name | <3-24 chars> |
azure-tenant-id | Azure tenant ID | ********-****-****-****-************ |
civo-api-key | Civo API key | <50 chars> |
cloudflare-api-key | Cloudflare API Key | **************************************** |
cloudflare-global-api-key | Cloudflare Global API Key | ************************************* |
cloudflare-origin-ca-key | Cloudflare Origin CA Key | v1.0-************************-<146 chars> |
defined-networking-api-token | Defined Networking API token | dnkey-**************************-<52 chars> |
deno-account-token | Deno account token | ddp_************************************ |
digitalocean-access-token | DigitalOcean OAuth Access Token | doo_v1_<64 chars> |
digitalocean-pat | DigitalOcean Personal Access Token | dop_v1_<64 chars> |
digitalocean-refresh-token | DigitalOcean OAuth Refresh Token | dor_v1_<64 chars> |
docker-swarm-join-token | Docker Swarm join token | SWMTKN-1-<50-60 chars>-<24-30 chars> |
docker-swarm-unlock-key | Docker Swarm unlock key | SWMKEY-1-<40-50 chars> |
dockerhub-organization-access-token | Docker Hub organization access token | dckr_oat_******************************** |
dockerhub-personal-access-token | Docker Hub personal access token | dckr_pat_*************************** |
exoscale-api-key | Exoscale API key | EXO<24-30 chars> |
exoscale-api-secret | Exoscale API secret | <40-60 chars> |
fastly-api-token | Fastly API key | ******************************** |
flyio-access-token | Fly.io API key | FlyV1<101+ chars> |
gcp-api-key | Google Cloud Platform API Key | AIza*********************************** |
gcp-application-default-credentials | Google Cloud application default credentials | {"client_secret": "<secret>", "refresh_token": "<token>"} |
gcp-cloud-storage-interoperability-access-key | Google Cloud Storage interoperability access key | GOOG******************** |
gcp-service-account-json | GCP Service Account JSON | {"type": "service_account", "private_key": "-----BEGIN PRIVATE KEY-----<key>-----END PRIVATE KEY-----", "client_email": "<sa>@<project>.iam.gserviceaccount.com", ...} |
generic-service-json | Generic service account JSON | {"private_key": "-----BEGIN PRIVATE KEY-----<key>-----END PRIVATE KEY-----"} |
hashicorp-tf-api-token | HashiCorp Terraform user/org API token | **************.atlasv1.<60-70 chars> |
hashicorp-tf-password | HashiCorp Terraform password | "<8-20 chars>" |
heroku-api-key | Heroku Platform API Key | ********-****-****-****-************ |
heroku-api-key-v2 | Heroku API key (v2 format) | HRKU-AA<58 chars> |
ibm-cloud-user-api-key | IBM Cloud user API key | <42-44 chars> |
infomaniak-api-token | Infomaniak API token | <60-100 chars> |
infracost-api-token | Infracost API Token | ico-******************************** |
kubernetes-secret-yaml | Kubernetes Secret manifest (YAML) | kind: Secret ... data: <name>: <base64 value> |
netlify-access-token | Netlify Access Token | <40-46 chars> |
openshift-user-token | OpenShift user token | sha256~<43 chars> |
ovh-application-key | OVHcloud application key | **************** |
ovh-application-secret | OVHcloud application secret | ******************************** |
ovh-consumer-key | OVHcloud consumer key | ******************************** |
pulumi-api-token | Pulumi API token | pul-**************************************** |
render-api-key | Render API key | rnd_**************************** |
scaleway-secret-key | Scaleway secret key | ********-****-****-****-************ |
scalingo-api-token | Scalingo API token | tk-us-<48 chars> |
scalr-api-access-token | Scalr API access token | eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ1c2VyIiwianRpIjoiYXQt<20-40 chars>.<43 chars> |
tailscale-api-key | Tailscale API key | tskey-api-<20-36 chars> |
temporal-cloud-api-key | Temporal Cloud API key | eyJ<header>.<payload>.<signature> |
upcloud-api-token | UpCloud API token | ucat_<24-32 chars> |
val-town-api-token | Val Town API token | vtwn_<20-80 chars> |
vault-batch-token | HashiCorp Vault Batch Token | hvb.<138-300 chars> |
vault-service-token | HashiCorp Vault Service Token | hvs.<90-120 chars> |
vercel-api-token | Vercel API token | ************************ |
vercel-app-access-token | Vercel app access token | vca_<56 chars> |
vercel-app-refresh-token | Vercel app refresh token | vcr_<56 chars> |
vercel-integration-token | Vercel integration token | vci_<56 chars> |
vercel-personal-access-token | Vercel personal access token | vcp_<56 chars> |
Databases & data platforms
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
clickhouse-cloud-api-secret-key | ClickHouse Cloud API secret key | 4b1d************************************** |
clickhouse-cloud-key-id | ClickHouse Cloud key ID | ******************** |
cockroachlabs-cloud-api-key | CockroachDB Cloud API key | CCDB1_**********************_**************************************** |
couchbase-capella-api-key | Couchbase Capella API key | <60-120 chars> |
databento-api-key | Databento API key | db-***************************** |
databricks-api-token | Databricks API token | dapi******************************** |
datagov-api-key | Data.gov API key | **************************************** |
datastax-astra-application-token | DataStax Astra application token | AstraCS:<20+ chars> |
influxdb-api-token | InfluxDB API token | <88+ chars> |
mongodb-atlas-service-account-id | MongoDB Atlas service account ID | mdb_sa_id_************************ |
mongodb-atlas-service-account-secret | MongoDB Atlas service account secret | mdb_sa_sk_**************************************** |
mongodb-connection-string | MongoDB connection string | mongodb://<username>:<password>@<host>:<port>/<database> |
neon-api-key | Neon API key | napi_<64 chars> |
planetscale-api-token | PlanetScale API token | pscale_tkn_<32-64 chars> |
planetscale-id | PlanetScale ID | ************ |
planetscale-oauth-token | PlanetScale OAuth token | pscale_oauth_<32-64 chars> |
planetscale-password | PlanetScale password | pscale_pw_<32-64 chars> |
snowflake-account-host | Snowflake account host | <account>.<region>.snowflakecomputing.com |
snowflake-programmatic-access-token | Snowflake programmatic access token | <100-500 chars> |
supabase-management-token | Supabase management token | sbp_**************************************** |
supabase-project-api-key | Supabase project API key | sb_secret_******************************* |
supabase-project-url | Supabase project URL | https://<project-ref>.supabase.co |
Source control, CI/CD & package registries
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
aikido-ci-token | Aikido CI token | AIK_CI_<20-44 chars> |
aikido-client-id | Aikido client ID | AIK_CLIENT_************************ |
aikido-client-secret | Aikido client secret | AIK_SECRET_<64 chars> |
artifactory-api-key | JFrog Artifactory API key | AKCp<68-70 chars> |
artifactory-jfrog-url | JFrog Artifactory instance URL | <instance>.jfrog.io |
artifactory-reference-token | JFrog Artifactory reference token | cmVmd<59 chars> |
bitbucket-client-id | Bitbucket Client ID | ******************************** |
bitbucket-client-secret | Bitbucket Client Secret | <64 chars> |
bitrise-access-token | Bitrise access token | <60-120 chars> |
buildkite-service-token | Buildkite service token | bkaa_<75 chars> |
buildkite-user-access-token | Buildkite user access token | bkua_**************************************** |
circleci-personal-token | CircleCI personal token | CCIPAT_**********************_**************************************** |
circleci-project-token | CircleCI project token | **************************************** |
clojars-api-token | Clojars API token | CLOJARS_<60 chars> |
cloudsmith-api-key | Cloudsmith API key | csa_************************************ |
codecov-access-token | Codecov Access Token | ************************************ |
coveralls-personal-api-token | Coveralls personal API token | ************************************* |
crates-io-api-key | crates.io API key | cio******************************** |
droneci-access-token | Droneci Access Token | ******************************** |
gitea-access-token | Gitea access token | **************************************** |
github-app-token | GitHub App Token | ghu_************************************ |
github-fine-grained-pat | GitHub Fine-Grained Personal Access Token | github_pat_<82 chars> |
github-oauth | GitHub OAuth Access Token | gho_************************************ |
github-pat | GitHub Personal Access Token (Classic) | ghp_************************************ |
github-refresh-token | GitHub Refresh Token | ghr_************************************ |
gitlab-cicd-job-token | GitLab CI/CD Job Token | glcbt-<1-5 chars>_******************** |
gitlab-deploy-token | GitLab Deploy Token | gldt-******************** |
gitlab-feature-flag-client-token | GitLab feature flag client token | glffct-******************** |
gitlab-feed-token | GitLab feed token | glft-******************** |
gitlab-kubernetes-agent-token | GitLab Kubernetes Agent token | glagent-<50 chars> |
gitlab-oauth-app-secret | GitLab OIDC Application Secret | gloas-<64 chars> |
gitlab-pat | GitLab Personal Access Token | glpat-******************** |
gitlab-pat-routable | GitLab Personal Access Token (routable) | glpat-<27-300 chars>.********* |
gitlab-pat-routable-versioned | GitLab personal access token (routable, versioned) | glpat-<27-300 chars>.**.********* |
gitlab-ptt | GitLab Pipeline Trigger Token | glptt-**************************************** |
gitlab-rrt | GitLab Runner Registration Token | GR1348941******************** |
gitlab-runner-authentication-token | GitLab Runner Authentication Token | glrt-******************** |
gitlab-runner-authentication-token-routable | GitLab Runner authentication token (routable) | glrt-t*_<27-300 chars>.********* |
gitlab-scim-token | GitLab SCIM Token | glsoat-******************** |
gitlab-session-cookie | GitLab Session Cookie | _gitlab_session=******************************** |
harness-api-key | Harness Access Token (PAT or SAT) | pat.**********************.************************.******************** |
ionic-personal-access-token | Ionic personal access token | ion_<42 chars> |
mergify-application-key | Mergify application key | mergify_application_key_<40-200 chars> |
npm-access-token | npm access token | npm_************************************ |
nuget-config-password | NuGet config password | <add key="ClearTextPassword" value="<password>" /> |
octopus-deploy-api-key | Octopus Deploy API key | API-************************** |
prefect-api-token | Prefect API token | pnu_************************************ |
pypi-upload-token | PyPI upload token | pypi-AgEIcHlwaS5vcmc<50-1000 chars> |
rubygems-api-token | Rubygem API token | rubygems_<48 chars> |
sonar-api-token | SonarQube/SonarCloud API token | **************************************** |
sourcegraph-access-token | Sourcegraph access token | sgp_local_**************************************** |
thunderstore-api-token | Thunderstore API token | tss_<20-80 chars> |
travisci-access-token | Travis CI Access Token | ********************** |
Developer tooling, observability & security
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
1password-secret-key | 1Password secret key | A3-******-***********-*****-*****-***** |
1password-service-account-token | 1Password service account token | ops_eyJ<250+ chars> |
adafruit-api-key | Adafruit API Key | ******************************** |
aiven-auth-token | Aiven auth token | <372 chars> |
algolia-api-key | Algolia API Key | ******************************** |
algolia-application-id | Algolia application ID | ********** |
atlassian-api-token | Atlassian API token (Jira, Confluence) | ATATT3<186 chars> |
authress-service-client-access-key | Authress Service Client Access Key | sc_<5-30 chars>.<4-6 chars>.acc<11-33 chars>.<30-120 chars> |
beamer-api-token | Beamer API token | b_<44 chars> |
clerk-secret-key | Clerk secret key | sk_live_******************************** |
configcat-sdk-key | ConfigCat SDK key | **********************/********************** |
configcat-sdk-key-extended | ConfigCat SDK key (extended format) | configcat-sdk-1/**********************/********************** |
curl-auth-header | Authorization token in a curl command header | curl -H "Authorization: Bearer <token>" |
curl-auth-user | Basic authorization credentials in a curl command | curl -u <username>:<password> |
datadog-api-key | Datadog API key | ******************************** |
datadog-application-key | Datadog application key | **************************************** |
devcycle-client-sdk-key | DevCycle client SDK key | dvc_client_<8-32 chars> |
devcycle-mobile-sdk-key | DevCycle mobile SDK key | dvc_mobile_<8-32 chars> |
devcycle-server-sdk-key | DevCycle server SDK key | dvc_server_<8-32 chars> |
doppler-api-token | Doppler API token | dp.pt.<43 chars> |
dynatrace-api-token | Dynatrace API token | dt0c01.************************.<64 chars> |
elastic-cloud-api-key | Elastic Cloud API key | essu_<60-200 chars> |
endorlabs-api-key | Endor Labs API key | endr+**************** |
endorlabs-api-secret | Endor Labs API secret | endr+**************** |
frameio-api-token | Frame.io API token | fio-u-<64 chars> |
freemius-secret-key | Freemius secret key (in PHP context) | sk_***************************** |
grafana-api-key | Grafana API key | eyJrIjoi<40-380 chars> |
grafana-cloud-api-token | Grafana cloud API token | glc_<40-150 chars> |
grafana-service-account-token | Grafana service account token | glsa_********************************_******** |
honeycomb-api-key | Honeycomb API key | ******************************** |
jumpcloud-api-key | JumpCloud API key | **************************************** |
launchdarkly-access-token | Launchdarkly Access Token | **************************************** |
linear-api-key | Linear API Token | lin_api_**************************************** |
linear-client-secret | Linear Client Secret | ******************************** |
new-relic-browser-api-token | New Relic ingest browser API token | NRJS-******************* |
new-relic-insert-key | New Relic insight insert key | NRII-******************************** |
new-relic-user-api-id | New Relic user API ID | <64 chars> |
new-relic-user-api-key | New Relic user API Key | NRAK-*************************** |
okta-access-token | Okta Access Token | 00**************************************** |
postman-api-token | Postman API token | PMAK-************************-********************************** |
proof-full-access-api-key | Proof full access API key | prf_<20-80 chars> |
rapidapi-access-token | RapidAPI Access Token | <50 chars> |
readme-api-token | Readme API token | rdme_<70 chars> |
redirect-pizza-api-token | Redirect.pizza API token | rpa_****************************** |
rootly-api-key | Rootly API key | rootly_<64 chars> |
sentry-access-token | Sentry.io Access Token (old format) | <64 chars> |
sentry-org-token | Sentry.io Organization Token | sntrys_eyJpYXQiO<10-200 chars>LCJyZWdpb25fdXJs<10-200 chars>_<43 chars> |
sentry-user-token | Sentry.io User Token | sntryu_<64 chars> |
settlemint-application-access-token | Settlemint Application Access Token | sm_aat_**************** |
settlemint-personal-access-token | Settlemint Personal Access Token | sm_pat_**************** |
settlemint-service-access-token | Settlemint Service Access Token | sm_sat_**************** |
sidekiq-secret | Sidekiq Secret (Enterprise/Gems Bundle Auth) | ********:******** |
sidekiq-sensitive-url | Sidekiq sensitive URL | redis://<username>:<password>@<host>:<port> |
snyk-api-token | Snyk API token | ********-****-****-****-************ |
sslmate-api-key | SSLMate API key | ************************************ |
sumologic-access-id | SumoLogic Access ID | su************ |
sumologic-access-token | SumoLogic Access Token | <64 chars> |
typeform-api-token | Typeform API token | tfp_<59 chars> |
unkey-root-key | Unkey root key | unkey_<20-32 chars> |
wakatime-api-key | WakaTime API key | waka_<36-64 chars> |
workato-developer-api-token | Workato developer API token | wrka<0-2 chars>-eyJ<8+ chars>.<16+ chars>.<64+ chars> |
workos-production-api-key | WorkOS production API key | sk_live_a2V5Xz<69 chars> |
zuplo-consumer-api-key | Zuplo consumer API key | zpka_********************************_******** |
Payments, fintech & identity verification
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
asaas-api-token | Asaas API token | $aact_prod_<20-100 chars> |
bittrex-access-key | Bittrex Access Key | ******************************** |
bittrex-secret-key | Bittrex Secret Key | ******************************** |
checkout-secret-key | Checkout.com secret key | sk_********-****-****-****-************ |
coinbase-access-token | Coinbase Access Token | <64 chars> |
duffel-api-token | Duffel API token | duffel_live_<43 chars> |
finicity-api-token | Finicity API token | ******************************** |
finicity-client-secret | Finicity Client Secret | ******************** |
finnhub-access-token | Finnhub Access Token | ******************** |
flutterwave-encryption-key | Flutterwave Encryption Key (Test) | FLWSECK_TEST-************ |
flutterwave-public-key | Flutterwave Public Key (Test) | FLWPUBK_TEST-********************************-X |
flutterwave-secret-key | Flutterwave Secret Key (Test) | FLWSECK_TEST-********************************-X |
freshbooks-access-token | Freshbooks Access Token | <64 chars> |
gocardless-api-token | GoCardless API token | live_**************************************** |
gumroad-access-token | Gumroad access token | <64 chars> |
highnote-secret-live-key | Highnote live secret key | sk_live_a2V5Xz<69 chars> |
kraken-access-token | Kraken Access Token | <80-90 chars> |
kucoin-access-token | Kucoin Access Token | ************************ |
kucoin-secret-key | Kucoin Secret Key | ********-****-****-****-************ |
mercury-production-api-token | Mercury production API token | mercury_production_<3-6 chars>_<40-50 chars>_yrucrem |
midtrans-production-server-client-key | Midtrans production server client key | Mid-server-<10-20 chars> |
onfido-live-api-token-ca | Onfido live API token CA | api_live_ca.<20-80 chars> |
onfido-live-api-token-eu | Onfido live API token EU | api_live.<20-80 chars> |
onfido-live-api-token-us | Onfido live API token US | api_live_us.<20-80 chars> |
paddle-live-api-key | Paddle live API key | pdl_live_apikey_**************************_**********************_*** |
persona-production-api-key | Persona production API key | persona_production_<20-80 chars> |
plaid-api-token | Plaid API Token | access-development-********-****-****-****-************ |
plaid-client-id | Plaid Client ID | ************************ |
plaid-secret-key | Plaid Secret key | ****************************** |
polar-oauth-access-token | Polar OAuth access token | polar_at_<20-100 chars> |
polar-organization-access-token | Polar organization access token | polar_oat_<20-100 chars> |
polar-personal-access-token | Polar personal access token | polar_pat_<20-100 chars> |
polymarket-address | Polymarket wallet address | 0x**************************************** |
polymarket-api-key | Polymarket API key | ********-****-****-****-************ |
polymarket-api-secret | Polymarket API secret | <40+ chars> |
polymarket-passphrase | Polymarket passphrase | <8-128 chars> |
polymarket-private-key | Polymarket private key | 0x<64 chars> |
rainforest-pay-production-api-key | Rainforest Pay production API key | apikey_<64 chars> |
ramp-client-id | Ramp client ID | ramp_id_**************************************** |
ramp-client-secret | Ramp client secret | ramp_sec_<48 chars> |
square-access-token | Square Access Token | EAAA<22-60 chars> |
stripe-access-token | Stripe API Key (Secret or Restricted) | sk_live_<10-99 chars> |
Communication, collaboration & productivity
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
asana-client-id | Asana Client ID | **************** |
asana-client-secret | Asana Client Secret | ******************************** |
box-api-access-token | Box API access token | ******************************** |
canva-client-id | Canva client ID | OC-<8-16 chars> |
canva-client-secret | Canva client secret | cnvca<51 chars> |
clickup-personal-api-token | ClickUp personal API token | pk_<8-9 chars>_******************************** |
discord-api-token | Discord API Key | <64 chars> |
discord-client-id | Discord client ID | ****************** |
discord-client-secret | Discord client secret | ******************************** |
figma-personal-access-header-token | Figma personal access header token | ****-********-****-****-****-************ |
figma-personal-access-token | Figma personal access token | figd_<38-42 chars> |
gitter-access-token | Gitter Access Token | **************************************** |
intercom-api-key | Intercom API Token | <60 chars> |
lark-app-id | Lark app ID | cli_**************** |
lark-app-secret | Lark app secret | ******************************** |
mailchimp-api-key | Mailchimp API key | ********************************-us** |
mailersend-api-token | MailerSend API token | mlsn.<30-100 chars> |
mailgun-private-api-token | Mailgun private API token | key-******************************** |
mailgun-pub-key | Mailgun public validation key | pubkey-******************************** |
mailgun-signing-key | Mailgun webhook signing key | ********************************-********-******** |
mattermost-access-token | Mattermost Access Token | ************************** |
messagebird-api-token | MessageBird API token | ************************* |
messagebird-client-id | MessageBird client ID | ********-****-****-****-************ |
microsoft-teams-webhook | Microsoft Teams Webhook URL | https://<tenant>.webhook.office.com/webhookb2/<uuid>@<uuid>/IncomingWebhook/<32 chars>/<uuid> |
notion-api-token | Notion API token | ntn_<46 chars> |
onesignal-rich-authentication-token | OneSignal rich authentication token | os_v2_app_<103 chars> |
plivo-auth-id | Plivo auth ID | MA****************** |
plivo-auth-token | Plivo auth token | **************************************** |
sendbird-access-id | Sendbird Access ID | ********-****-****-****-************ |
sendbird-access-token | Sendbird Access Token | **************************************** |
sendgrid-api-token | SendGrid API token | SG.<66 chars> |
sendinblue-api-token | Sendinblue API token | xkeysib-<64 chars>-**************** |
slack-app-token | Slack App-level token | xapp-1-<app id>-<number>-<hash> |
slack-bot-token | Slack Bot token | xoxb-<10-13 chars>-<10+ chars> |
slack-config-access-token | Slack Configuration access token | xoxe*xox*-*-<163-166 chars> |
slack-config-refresh-token | Slack Configuration refresh token | xoxe-*-<146 chars> |
slack-legacy-bot-token | Slack Legacy bot token | xoxb-<8-14 chars>-<18-26 chars> |
slack-legacy-token | Slack Legacy token (Test) | xoxp-<digits>-<digits>-<digits>-<hash> |
slack-legacy-workspace-token | Slack Legacy Workspace token | xox*-<8-48 chars> |
slack-session-cookie | Slack session cookie | xoxd-<100+ chars> |
slack-session-token | Slack session token | xoxc-<9-15 chars>-<9-15 chars>-<9-15 chars>-<64 chars> |
slack-user-token | Slack User token | xox*-<10-13 chars>-<10-13 chars>-<10-13 chars>-<28-34 chars> |
slack-webhook-url | Slack webhook URL | hooks*slack*com/services/<43-56 chars> |
telegram-bot-api-token | Telegram Bot API Token | <5-16 chars>:A********************************** |
telnyx-api-v2-key | Telnyx API v2 key | KEY<55 chars> |
twilio-api-key | Twilio API Key SID | SK******************************** |
zendesk-secret-key | Zendesk Secret Key | **************************************** |
Marketing, analytics, commerce & consumer services
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
adobe-client-id | Adobe OAuth Web Client ID | ******************************** |
adobe-client-secret | Adobe Client Secret | p8e-******************************** |
airtable-api-key | Airtable API Key | ***************** |
airtable-oauth-token | Airtable OAuth token | <token id>.v1.<payload>.<signature> |
airtable-personnal-access-token | Airtable personal access token | pat**************.<64 chars> |
amplitude-secret-key | Amplitude secret key | ******************************** |
apify-api-token | Apify API token | apify_api_<34-38 chars> |
bitly-access-token | Bitly access token | **************************************** |
canadian-digital-service-notify-api-key | Canadian Digital Service Notify API key | ApiKey-v1_gcntfy-<name>-<uuid>-<uuid> |
cisco-meraki-api-key | Cisco Meraki API Key | **************************************** |
cloudinary-api-key | Cloudinary API key | *************** |
cloudinary-api-secret | Cloudinary API secret | ******************************** |
cloudinary-cloud-name | Cloudinary cloud name | <3-32 chars> |
confluent-access-token | Confluent Access Token | **************** |
confluent-secret-key | Confluent Secret Key | <64 chars> |
contentful-delivery-api-token | Contentful delivery API token | <43 chars> |
disqus-api-key | Disqus API key | <64 chars> |
dropbox-api-token | Dropbox API secret | *************** |
dropbox-long-lived-api-token | Dropbox long-lived API token | ***********AAAAAAAAAA<43 chars> |
dropbox-short-lived-api-token | Dropbox short-lived API token | sl.<135 chars> |
easypost-api-token | EasyPost API token | EZAK<54 chars> |
easypost-test-api-token | EasyPost test API token | EZTK<54 chars> |
ebay-client-id | eBay client ID | <app name>-<id>-PRD-<8-12 chars>-<8-12 chars> |
ebay-client-secret | eBay client secret | PRD-********-****-****-****-<4-12 chars> |
etsy-open-api-key | Etsy Open API key | ************************:<10-64 chars> |
facebook-access-token | Facebook Access Token (Legacy) | <15-16 chars>|<27-40 chars> |
facebook-page-access-token | Facebook Page Access Token | EAA<101+ chars> |
facebook-secret | Facebook Application secret | ******************************** |
flickr-access-token | Flickr Access Token | ******************************** |
fullstory-api-key | FullStory API key | na1.<20+ chars> |
hubspot-api-key | HubSpot API Token | ********-****-****-****-************ |
intra42-client-secret | Intra42 client secret | s-s4t2ud-<64 chars> |
klaviyo-api-key | Klaviyo API key | pk_********************************** |
lichess-personal-access-token | Lichess personal access token | lip_<16-60 chars> |
linkedin-client-id | LinkedIn Client ID | ************** |
linkedin-client-secret | LinkedIn Client secret | **************** |
lob-api-key | Lob API Key (Live or Test) | live_*********************************** |
lob-pub-api-key | Lob Publishable API Key (Live or Test) | live_pub_******************************* |
looker-client-id | Looker client ID | ******************** |
looker-client-secret | Looker client secret | ************************ |
mapbox-api-token | MapBox API token | pk.<60 chars>.********************** |
maxmind-license-key | MaxMind license key | ******_*****************************_mmk |
nytimes-access-token | Nytimes Access Token | ******************************** |
openweather-api-key | OpenWeather API key | ******************************** |
pinterest-access-token | Pinterest access token | pina_<20-200 chars> |
posthog-personal-api-key | PostHog personal API key | phx_<41-49 chars> |
posthog-project-api-key | PostHog project API key | phc_<41-44 chars> |
salesforce-access-token | Salesforce access token | 00*************!<80-260 chars> |
salesforce-instance-url | Salesforce instance URL | <instance>.my.salesforce.com |
samsara-api-token | Samsara API token | samsara_api_<26-32 chars> |
segment-public-api-token | Segment public API token | sgp_<64 chars> |
shippo-api-token | Shippo API token (Live or Test) | shippo_live_**************************************** |
shopify-access-token | Shopify Admin API Access Token | shpat_******************************** |
shopify-custom-access-token | Shopify custom access token | shpca_******************************** |
shopify-private-app-access-token | Shopify private app access token | shppa_******************************** |
shopify-shared-secret | Shopify shared secret | shpss_******************************** |
squarespace-access-token | Squarespace Access Token | ********-****-****-****-************ |
tableau-personal-access-token | Tableau personal access token | **********************==:******************************** |
tableau-personal-access-token-name | Tableau personal access token name | <3-51 chars> |
tableau-server-host | Tableau server host | <site>.online.tableau.com |
twitch-api-token | Twitch API token | ****************************** |
twitter-access-secret | Twitter Access Secret | <45 chars> |
twitter-access-token | Twitter Access Token | <15-25 chars>-<20-40 chars> |
twitter-api-key | Twitter API Key (Consumer Key) | ************************* |
twitter-api-secret | Twitter API Secret (Consumer Secret) | <50 chars> |
twitter-bearer-token | Twitter Bearer Token | AAA<80-100 chars> |
weatherstack-api-key | Weatherstack API key | ******************************** |
yandex-access-token | Yandex Access Token | t1.<segment>.<86-88 chars> |
yandex-api-key | Yandex API Key | AQVN<35-38 chars> |
yandex-aws-access-token | Yandex AWS Access Token | YC************************************** |
Cryptographic keys & generic credentials
| Secret Type (Rule ID) | Description | Example Format |
|---|---|---|
age-secret-key | Age encryption tool secret key | AGE-SECRET-KEY-1<58 chars> |
pkcs12-file | PKCS#12 keystore file | <filename>.p12 or <filename>.pfx |
private-key | Generic Private Key | -----BEGIN PRIVATE KEY-----<base64 key material>-----END PRIVATE KEY----- |
Types that never appear in results
Three of the types listed above are accepted by the type parameter but cannot currently be returned, so a query filtered to them will always come back empty:
azure-client-id— the detection rule is disabled. It matched any UUID sitting near aclient_idkeyword, which produced too many false positives in infostealer logs. It exists only as a helper for validating Azure service principals, never as a standalone finding.generic-service-json— every match is re-validated as a GCP service account. It is either promoted togcp-service-account-jsonor discarded, so it is never stored under its own type.gcp-cloud-storage-interoperability-access-key— matches are logged for investigation but deliberately not stored.
One further type is conditional: aws-secret-key is only stored when an aws-access-token is found in the same source file, because a bare 40-character string cannot reliably be told apart from other Base64 data.
System Information
Details about the infected device:
- OS version
- IP address
- Hardware information (HWID, Machine ID)
- System language and settings
User Information
Personal details of the victim:
- Device Username
- Full name (if available)
- Location (derived from IP)
Stolen Files
Documents, source code, configuration files, and other sensitive files exfiltrated from the device:
- Personal documents
- Financial records
- Business information
- Source code repositories
- Configuration files (
.env,.aws/credentials, etc.)
Data Example
Below is the Secrets tab of a Redline infection, alongside the counts of credentials, cookies, autofills and other artefacts recovered from the same device:

Each row pairs a rule ID from the Detected Secret Types tables with the recovered value. This infection yielded five values across four types: a Groq API key, two OpenAI project keys, a Stripe key, and a MongoDB connection string. The sidebar counts secrets by type, which is why it reads four while the table lists five rows.
Security Implications
Malware infection data presents unique and severe threats:
- Immediate Risk: Credentials and cookies are often current and immediately usable for account takeover.
- Session Hijacking: Stolen cookies can allow account access without credentials, bypassing MFA.
- Multiple Service Exposure: A single infection can compromise dozens of services used by one individual.
- Corporate Network Access: Infected employee devices may expose enterprise credentials, VPN keys, or internal service tokens.
- Infrastructure Compromise: Leaked secrets (API keys, private keys, service tokens) found in files can grant attackers direct access to cloud environments, databases, code repositories, and other critical infrastructure, potentially leading to widespread breaches or system manipulation.
- Source Code Exposure: Stolen source code can reveal proprietary algorithms or further vulnerabilities.
API Access Methods
The NordStellar Dark Web API provides multiple ways to access malware infection information, including detected secrets:
Direct Lookups
- Query for specific email addresses using the
/email/{email-sha256}/malware-logsendpoint. - Query for specific phone numbers using the
/phone/{phone-sha256}/malware-logsendpoint. - Get detailed malware log information, including the
secretarray containing detected secret types and values, using the/data-source/malware-log/{id}endpoint.
Bulk Operations
- Check multiple email addresses in a single request using the
/email/malware-logs(POST) endpoint. - Check multiple phone numbers in a single request using the
/phone/malware-logs(POST) endpoint. - Retrieve information about multiple malware logs using the
/data-source/malware-log(POST) endpoint. - Retrieve metadata only, without the full stolen-data payload, using the
/data-source/malware-log/details(POST) endpoint. - Retrieve per-log counts using the
/data-source/malware-log/stats(POST) endpoint.
Secret Lookups
Secrets are returned inside the secret array of the full malware log, and dedicated endpoints also let you query them directly without retrieving the entire log:
- Find the IDs of malware logs containing any secret using the
/data-source/malware-log/secrets/type/idendpoint. - Find the IDs of malware logs containing a specific secret type using the
/data-source/malware-log/secrets/type/{type}/idendpoint. - Retrieve all secrets from a single malware log using the
/data-source/malware-log/{id}/secrets/typeendpoint. - Retrieve secrets of a specific type from a single malware log using the
/data-source/malware-log/{id}/secrets/type/{type}endpoint. - Page through secrets across many logs using the
/data-source/malware-log/secrets/feed(POST) endpoint.
The {type} path parameter accepts any of the rule IDs listed under Detected Secret Types.
Specialized Queries
- Search for credentials associated with specific URLs using the
/data-source/malware-log/credentials/url/{credentials_url}/idendpoint. - Retrieve specific credential details using the
/data-source/malware-log/{id}/credentials/url/{credentials_url}endpoint. - Page through credentials across many logs using the
/data-source/malware-log/credentials/feed(POST) endpoint.
Trimming Large Responses
Malware logs can be very large. The endpoints that return full log data accept two mutually exclusive query parameters to control the payload:
inclusive-projectionreturns only the listed fields, for example?inclusive-projection=credentials,secrets.exclusive-projectionreturns everything except the listed fields, for example?exclusive-projection=cookies,grabbed_files.
Both accept a comma-separated list or repeated parameters. The id field is always returned and cannot be excluded.
Use Cases
Account Protection
- Identify and lock down compromised user accounts based on stolen credentials.
- Force password resets for affected services.
- Invalidate stolen browser cookies to prevent session hijacking.
Infrastructure Security & Secret Management
- Detect Exposed Secrets: Monitor malware logs for leaked API keys, tokens, or private keys related to your corporate infrastructure (e.g., AWS keys, GitHub tokens found on developer machines).
- Rapid Revocation: Immediately revoke compromised secrets identified in malware logs to prevent unauthorized access.
- Improve Secret Hygiene: Use findings as indicators of poor secret management practices (e.g., hardcoding secrets in source code found on infected devices).
Threat Intelligence
- Gain insights into active malware campaigns targeting specific services or user groups.
- Identify targeted organizations and the types of credentials or secrets attackers are harvesting.
- Understand the capabilities and targets of different infostealer variants.
Incident Response
- Determine the scope of a malware infection by identifying all affected accounts, services, and potentially exposed secrets.
- Assess the potential damage from stolen credentials, cookies, and secrets.
- Prioritize remediation based on the sensitivity of exposed data and secrets.
Corporate Security
- Monitor for corporate credential and secret exposure from employee device infections.
- Identify infected devices that may have access to corporate resources or codebases containing secrets.
- Detect breached VPN, cloud service, internal system credentials, or API keys.
By leveraging malware infection data, including the critical aspect of leaked secrets, through the NordStellar Dark Web API, organizations can rapidly respond to active threats, protect user accounts and infrastructure, and gain valuable intelligence about the evolving threat landscape.