Skip to main content
Enterprise APIs
Dark Web API
Data Categories
Malware Infections

Malware Infections (Infostealers)

Overview

Malware infection data comes from information-stealing malware (infostealers) that capture sensitive data from infected devices and transmit it to threat actors. This data offers unique insights into compromised credentials, cookies, system information, and leaked secrets that may not appear in traditional database breaches.

Characteristics

  • Origin: Data captured by malware from infected user devices.
  • Freshness: Often more recent than database breaches, representing active compromise.
  • Comprehensiveness: Can include data from multiple services accessed on the infected device, system details, and potentially sensitive files or source code.
  • Context: May include system information and behavioral data in addition to credentials and secrets.

Infostealer Types

Our system monitors data from 55+ different infostealer types, including:

  • RedLine
  • Meta
  • LummaC2
  • Vidar
  • Azorult
  • Raccoon
  • Cryptbot
  • And many more

Data Categories from Malware

Infostealers typically collect multiple types of sensitive information from infected devices:

Credentials

Stolen login information including:

  • Source application (browser or email client)
  • Website or service URL
  • Username/email
  • Plaintext password

Cookies

Browser cookies that can enable session hijacking:

  • Source browser
  • Website domain
  • Expiry details
  • Cookie values

Leaked Secrets

Hardcoded secrets found within files, configuration, or environment variables on the infected machine. These are often critical for accessing services and infrastructure:

  • Detection: We utilize specialized tools like Gitleaks, configured with a comprehensive set of rules, to scan files collected by infostealers. These rules are designed to identify patterns characteristic of various secret types.
  • Validation: Potential secrets undergo validation steps to reduce false positives and confirm the likelihood of a valid secret.
  • Types Detected: Common examples include API Keys & Tokens (AWS, GCP, Azure, GitHub, Slack, Stripe, Twilio, etc.), Private Keys (SSH, PGP), Database Credentials, Service Account Tokens (e.g., GCP, Vault), OAuth Tokens, and Configuration Secrets (e.g., Kubernetes secrets in YAML).

Detected Secret Types

The tables below list every secret type our system can currently detect within malware logs, grouped by the kind of service the credential unlocks. Each rule ID is the exact value returned in the type field of the secret array, and the exact value accepted by the type path parameter of the secrets endpoints.

The authoritative, always-current list is the type parameter of the secrets endpoints in the Dark Web API specification. New rule IDs appear there as detection rules ship, so check the specification if a type you expect is not listed here.

The Example Format column shows the shape a token takes, not a real value. Literal characters that a secret must contain are shown as-is, while variable characters are masked:

  • **** — a run of characters whose length is fixed by the pattern.
  • <N chars> — the same, where the run is too long to draw.
  • <N-M chars> — a run whose length varies between N and M.
  • <N+ chars> — a run of at least N characters, with no upper bound.
  • <description> — a structural element such as a hostname, username, or file name.
AI, machine learning & search
Secret Type (Rule ID)DescriptionExample Format
anthropic-admin-api-keyAnthropic admin API keysk-ant-admin01-<93 chars>AA
anthropic-api-keyAnthropic API keysk-ant-api03-<93 chars>AA
assemblyai-api-keyAssemblyAI API key********************************
aws-amazon-bedrock-api-key-long-livedAmazon Bedrock long-lived API keyABSK<109-269 chars>
aws-amazon-bedrock-api-key-short-livedAmazon Bedrock short-lived API keybedrock-api-key-YmVkcm9jay5hbWF6b25hd3MuY29t
brave-search-api-keyBrave Search API keyBSA<24-40 chars>
cerebras-api-keyCerebras API keycsk-<48 chars>
cohere-api-tokenCohere API Token****************************************
cursor-api-keyCursor API keykey_<64 chars>
deepgram-api-keyDeepgram API key****************************************
deepseek-api-keyDeepSeek API keysk-********************************
devin-personal-api-keyDevin personal API keyapk_user_<120-180 chars>
devin-service-api-keyDevin service API keyapk_<80-100 chars>
devin-service-user-tokenDevin service user tokencog_<52 chars>
elevenlabs-api-keyElevenLabs API keysk_<48 chars>
gcp-gemini-apiGoogle Gemini API keyAQ.Ab8RN6<44 chars>
greptile-api-keyGreptile API key<48 chars>
groq-api-keyGroq API keygsk_<52 chars>
huggingface-access-tokenHugging Face Access tokenhf_**********************************
huggingface-organization-api-tokenHugging Face Organization API tokenapi_org_**********************************
kagi-api-keyKagi API key***********.<43 chars>
kimi-api-keyKimi API keysk-<48 chars>
langchain-langsmith-personal-access-tokenLangSmith personal access tokenlsv2_pt_********************************_**********
langchain-langsmith-service-keyLangSmith service keylsv2_sk_********************************_**********
lighton-paradigm-api-keyLightOn Paradigm API key<40-80 chars>
minimax-api-keyMiniMax API keysk-api-<119 chars>
mistral-api-keyMistral AI API key********************************
nexos-ai-user-api-keynexos.ai user API keynexos-<128 chars>
nvidia-api-keyNVIDIA API keynvapi-<60-70 chars>
ollama-api-keyOllama API key********************************.************************
openai-api-keyOpenAI API Keysk-proj-<74 chars>T3BlbkFJ<74 chars>
openrouter-api-keyOpenRouter API keysk-or-v1-<64 chars>
perplexity-api-keyPerplexity API keypplx-<48 chars>
pinecone-api-keyPinecone API keypcsk_<5-6 chars>_<63 chars>
privateai-api-tokenPrivateAI API Token********************************
replicate-api-tokenReplicate API tokenr8_*************************************
runpod-api-keyRunPod API keyrpa_<46 chars>
stability-ai-api-keyStability AI API keysk-<48 chars>
togetherai-api-keyTogether AI API keytgp_v1_<43 chars>
upstage-api-keyUpstage API key<40-50 chars>
vercel-ai-gateway-keyVercel AI Gateway keyvck_<56 chars>
weights-and-biases-api-keyWeights & Biases API key****************************************
weights-and-biases-api-key-v1Weights & Biases API key (v1 format)wandb_v1_<77 chars>
xai-api-keyxAI API keyxai-<70-120 chars>
zai-api-keyZ.ai API key********************************.****************
Cloud providers & infrastructure
Secret Type (Rule ID)DescriptionExample Format
alibaba-access-key-idAlibaba Cloud AccessKey IDLTAI<17-21 chars>
alibaba-secret-keyAlibaba Cloud Secret Key******************************
alibaba-sts-access-key-idAlibaba Cloud STS access key IDSTS.<16-64 chars>
alibaba-sts-access-key-secretAlibaba Cloud STS access key secret<30-64 chars>
alibaba-sts-security-tokenAlibaba Cloud STS security tokenCAIS<20-1024 chars>
aws-access-tokenAWS Access Key IDAKIA****************
aws-secret-keyAWS Secret Key****************************************
azure-ad-client-secretAzure AD Client Secret****Q~<31-34 chars>
azure-app-configuration-connection-stringAzure app configuration connection stringEndpoint=https://<store>.azconfig.io;Id=<id>;Secret=<36-100 chars>
azure-client-idAzure client IDNot currently detected — see note below
azure-servicebus-connection-stringAzure Service Bus connection stringEndpoint=sb://<namespace>.servicebus.windows.net/;SharedAccessKeyName=<name>;SharedAccessKey=<32-100 chars>
azure-storage-account-keyAzure storage account key<86 chars>==
azure-storage-account-nameAzure storage account name<3-24 chars>
azure-tenant-idAzure tenant ID********-****-****-****-************
civo-api-keyCivo API key<50 chars>
cloudflare-api-keyCloudflare API Key****************************************
cloudflare-global-api-keyCloudflare Global API Key*************************************
cloudflare-origin-ca-keyCloudflare Origin CA Keyv1.0-************************-<146 chars>
defined-networking-api-tokenDefined Networking API tokendnkey-**************************-<52 chars>
deno-account-tokenDeno account tokenddp_************************************
digitalocean-access-tokenDigitalOcean OAuth Access Tokendoo_v1_<64 chars>
digitalocean-patDigitalOcean Personal Access Tokendop_v1_<64 chars>
digitalocean-refresh-tokenDigitalOcean OAuth Refresh Tokendor_v1_<64 chars>
docker-swarm-join-tokenDocker Swarm join tokenSWMTKN-1-<50-60 chars>-<24-30 chars>
docker-swarm-unlock-keyDocker Swarm unlock keySWMKEY-1-<40-50 chars>
dockerhub-organization-access-tokenDocker Hub organization access tokendckr_oat_********************************
dockerhub-personal-access-tokenDocker Hub personal access tokendckr_pat_***************************
exoscale-api-keyExoscale API keyEXO<24-30 chars>
exoscale-api-secretExoscale API secret<40-60 chars>
fastly-api-tokenFastly API key********************************
flyio-access-tokenFly.io API keyFlyV1<101+ chars>
gcp-api-keyGoogle Cloud Platform API KeyAIza***********************************
gcp-application-default-credentialsGoogle Cloud application default credentials{"client_secret": "<secret>", "refresh_token": "<token>"}
gcp-cloud-storage-interoperability-access-keyGoogle Cloud Storage interoperability access keyGOOG********************
gcp-service-account-jsonGCP Service Account JSON{"type": "service_account", "private_key": "-----BEGIN PRIVATE KEY-----<key>-----END PRIVATE KEY-----", "client_email": "<sa>@<project>.iam.gserviceaccount.com", ...}
generic-service-jsonGeneric service account JSON{"private_key": "-----BEGIN PRIVATE KEY-----<key>-----END PRIVATE KEY-----"}
hashicorp-tf-api-tokenHashiCorp Terraform user/org API token**************.atlasv1.<60-70 chars>
hashicorp-tf-passwordHashiCorp Terraform password"<8-20 chars>"
heroku-api-keyHeroku Platform API Key********-****-****-****-************
heroku-api-key-v2Heroku API key (v2 format)HRKU-AA<58 chars>
ibm-cloud-user-api-keyIBM Cloud user API key<42-44 chars>
infomaniak-api-tokenInfomaniak API token<60-100 chars>
infracost-api-tokenInfracost API Tokenico-********************************
kubernetes-secret-yamlKubernetes Secret manifest (YAML)kind: Secret ... data: <name>: <base64 value>
netlify-access-tokenNetlify Access Token<40-46 chars>
openshift-user-tokenOpenShift user tokensha256~<43 chars>
ovh-application-keyOVHcloud application key****************
ovh-application-secretOVHcloud application secret********************************
ovh-consumer-keyOVHcloud consumer key********************************
pulumi-api-tokenPulumi API tokenpul-****************************************
render-api-keyRender API keyrnd_****************************
scaleway-secret-keyScaleway secret key********-****-****-****-************
scalingo-api-tokenScalingo API tokentk-us-<48 chars>
scalr-api-access-tokenScalr API access tokeneyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ1c2VyIiwianRpIjoiYXQt<20-40 chars>.<43 chars>
tailscale-api-keyTailscale API keytskey-api-<20-36 chars>
temporal-cloud-api-keyTemporal Cloud API keyeyJ<header>.<payload>.<signature>
upcloud-api-tokenUpCloud API tokenucat_<24-32 chars>
val-town-api-tokenVal Town API tokenvtwn_<20-80 chars>
vault-batch-tokenHashiCorp Vault Batch Tokenhvb.<138-300 chars>
vault-service-tokenHashiCorp Vault Service Tokenhvs.<90-120 chars>
vercel-api-tokenVercel API token************************
vercel-app-access-tokenVercel app access tokenvca_<56 chars>
vercel-app-refresh-tokenVercel app refresh tokenvcr_<56 chars>
vercel-integration-tokenVercel integration tokenvci_<56 chars>
vercel-personal-access-tokenVercel personal access tokenvcp_<56 chars>
Databases & data platforms
Secret Type (Rule ID)DescriptionExample Format
clickhouse-cloud-api-secret-keyClickHouse Cloud API secret key4b1d**************************************
clickhouse-cloud-key-idClickHouse Cloud key ID********************
cockroachlabs-cloud-api-keyCockroachDB Cloud API keyCCDB1_**********************_****************************************
couchbase-capella-api-keyCouchbase Capella API key<60-120 chars>
databento-api-keyDatabento API keydb-*****************************
databricks-api-tokenDatabricks API tokendapi********************************
datagov-api-keyData.gov API key****************************************
datastax-astra-application-tokenDataStax Astra application tokenAstraCS:<20+ chars>
influxdb-api-tokenInfluxDB API token<88+ chars>
mongodb-atlas-service-account-idMongoDB Atlas service account IDmdb_sa_id_************************
mongodb-atlas-service-account-secretMongoDB Atlas service account secretmdb_sa_sk_****************************************
mongodb-connection-stringMongoDB connection stringmongodb://<username>:<password>@<host>:<port>/<database>
neon-api-keyNeon API keynapi_<64 chars>
planetscale-api-tokenPlanetScale API tokenpscale_tkn_<32-64 chars>
planetscale-idPlanetScale ID************
planetscale-oauth-tokenPlanetScale OAuth tokenpscale_oauth_<32-64 chars>
planetscale-passwordPlanetScale passwordpscale_pw_<32-64 chars>
snowflake-account-hostSnowflake account host<account>.<region>.snowflakecomputing.com
snowflake-programmatic-access-tokenSnowflake programmatic access token<100-500 chars>
supabase-management-tokenSupabase management tokensbp_****************************************
supabase-project-api-keySupabase project API keysb_secret_*******************************
supabase-project-urlSupabase project URLhttps://<project-ref>.supabase.co
Source control, CI/CD & package registries
Secret Type (Rule ID)DescriptionExample Format
aikido-ci-tokenAikido CI tokenAIK_CI_<20-44 chars>
aikido-client-idAikido client IDAIK_CLIENT_************************
aikido-client-secretAikido client secretAIK_SECRET_<64 chars>
artifactory-api-keyJFrog Artifactory API keyAKCp<68-70 chars>
artifactory-jfrog-urlJFrog Artifactory instance URL<instance>.jfrog.io
artifactory-reference-tokenJFrog Artifactory reference tokencmVmd<59 chars>
bitbucket-client-idBitbucket Client ID********************************
bitbucket-client-secretBitbucket Client Secret<64 chars>
bitrise-access-tokenBitrise access token<60-120 chars>
buildkite-service-tokenBuildkite service tokenbkaa_<75 chars>
buildkite-user-access-tokenBuildkite user access tokenbkua_****************************************
circleci-personal-tokenCircleCI personal tokenCCIPAT_**********************_****************************************
circleci-project-tokenCircleCI project token****************************************
clojars-api-tokenClojars API tokenCLOJARS_<60 chars>
cloudsmith-api-keyCloudsmith API keycsa_************************************
codecov-access-tokenCodecov Access Token************************************
coveralls-personal-api-tokenCoveralls personal API token*************************************
crates-io-api-keycrates.io API keycio********************************
droneci-access-tokenDroneci Access Token********************************
gitea-access-tokenGitea access token****************************************
github-app-tokenGitHub App Tokenghu_************************************
github-fine-grained-patGitHub Fine-Grained Personal Access Tokengithub_pat_<82 chars>
github-oauthGitHub OAuth Access Tokengho_************************************
github-patGitHub Personal Access Token (Classic)ghp_************************************
github-refresh-tokenGitHub Refresh Tokenghr_************************************
gitlab-cicd-job-tokenGitLab CI/CD Job Tokenglcbt-<1-5 chars>_********************
gitlab-deploy-tokenGitLab Deploy Tokengldt-********************
gitlab-feature-flag-client-tokenGitLab feature flag client tokenglffct-********************
gitlab-feed-tokenGitLab feed tokenglft-********************
gitlab-kubernetes-agent-tokenGitLab Kubernetes Agent tokenglagent-<50 chars>
gitlab-oauth-app-secretGitLab OIDC Application Secretgloas-<64 chars>
gitlab-patGitLab Personal Access Tokenglpat-********************
gitlab-pat-routableGitLab Personal Access Token (routable)glpat-<27-300 chars>.*********
gitlab-pat-routable-versionedGitLab personal access token (routable, versioned)glpat-<27-300 chars>.**.*********
gitlab-pttGitLab Pipeline Trigger Tokenglptt-****************************************
gitlab-rrtGitLab Runner Registration TokenGR1348941********************
gitlab-runner-authentication-tokenGitLab Runner Authentication Tokenglrt-********************
gitlab-runner-authentication-token-routableGitLab Runner authentication token (routable)glrt-t*_<27-300 chars>.*********
gitlab-scim-tokenGitLab SCIM Tokenglsoat-********************
gitlab-session-cookieGitLab Session Cookie_gitlab_session=********************************
harness-api-keyHarness Access Token (PAT or SAT)pat.**********************.************************.********************
ionic-personal-access-tokenIonic personal access tokenion_<42 chars>
mergify-application-keyMergify application keymergify_application_key_<40-200 chars>
npm-access-tokennpm access tokennpm_************************************
nuget-config-passwordNuGet config password<add key="ClearTextPassword" value="<password>" />
octopus-deploy-api-keyOctopus Deploy API keyAPI-**************************
prefect-api-tokenPrefect API tokenpnu_************************************
pypi-upload-tokenPyPI upload tokenpypi-AgEIcHlwaS5vcmc<50-1000 chars>
rubygems-api-tokenRubygem API tokenrubygems_<48 chars>
sonar-api-tokenSonarQube/SonarCloud API token****************************************
sourcegraph-access-tokenSourcegraph access tokensgp_local_****************************************
thunderstore-api-tokenThunderstore API tokentss_<20-80 chars>
travisci-access-tokenTravis CI Access Token**********************
Developer tooling, observability & security
Secret Type (Rule ID)DescriptionExample Format
1password-secret-key1Password secret keyA3-******-***********-*****-*****-*****
1password-service-account-token1Password service account tokenops_eyJ<250+ chars>
adafruit-api-keyAdafruit API Key********************************
aiven-auth-tokenAiven auth token<372 chars>
algolia-api-keyAlgolia API Key********************************
algolia-application-idAlgolia application ID**********
atlassian-api-tokenAtlassian API token (Jira, Confluence)ATATT3<186 chars>
authress-service-client-access-keyAuthress Service Client Access Keysc_<5-30 chars>.<4-6 chars>.acc<11-33 chars>.<30-120 chars>
beamer-api-tokenBeamer API tokenb_<44 chars>
clerk-secret-keyClerk secret keysk_live_********************************
configcat-sdk-keyConfigCat SDK key**********************/**********************
configcat-sdk-key-extendedConfigCat SDK key (extended format)configcat-sdk-1/**********************/**********************
curl-auth-headerAuthorization token in a curl command headercurl -H "Authorization: Bearer <token>"
curl-auth-userBasic authorization credentials in a curl commandcurl -u <username>:<password>
datadog-api-keyDatadog API key********************************
datadog-application-keyDatadog application key****************************************
devcycle-client-sdk-keyDevCycle client SDK keydvc_client_<8-32 chars>
devcycle-mobile-sdk-keyDevCycle mobile SDK keydvc_mobile_<8-32 chars>
devcycle-server-sdk-keyDevCycle server SDK keydvc_server_<8-32 chars>
doppler-api-tokenDoppler API tokendp.pt.<43 chars>
dynatrace-api-tokenDynatrace API tokendt0c01.************************.<64 chars>
elastic-cloud-api-keyElastic Cloud API keyessu_<60-200 chars>
endorlabs-api-keyEndor Labs API keyendr+****************
endorlabs-api-secretEndor Labs API secretendr+****************
frameio-api-tokenFrame.io API tokenfio-u-<64 chars>
freemius-secret-keyFreemius secret key (in PHP context)sk_*****************************
grafana-api-keyGrafana API keyeyJrIjoi<40-380 chars>
grafana-cloud-api-tokenGrafana cloud API tokenglc_<40-150 chars>
grafana-service-account-tokenGrafana service account tokenglsa_********************************_********
honeycomb-api-keyHoneycomb API key********************************
jumpcloud-api-keyJumpCloud API key****************************************
launchdarkly-access-tokenLaunchdarkly Access Token****************************************
linear-api-keyLinear API Tokenlin_api_****************************************
linear-client-secretLinear Client Secret********************************
new-relic-browser-api-tokenNew Relic ingest browser API tokenNRJS-*******************
new-relic-insert-keyNew Relic insight insert keyNRII-********************************
new-relic-user-api-idNew Relic user API ID<64 chars>
new-relic-user-api-keyNew Relic user API KeyNRAK-***************************
okta-access-tokenOkta Access Token00****************************************
postman-api-tokenPostman API tokenPMAK-************************-**********************************
proof-full-access-api-keyProof full access API keyprf_<20-80 chars>
rapidapi-access-tokenRapidAPI Access Token<50 chars>
readme-api-tokenReadme API tokenrdme_<70 chars>
redirect-pizza-api-tokenRedirect.pizza API tokenrpa_******************************
rootly-api-keyRootly API keyrootly_<64 chars>
sentry-access-tokenSentry.io Access Token (old format)<64 chars>
sentry-org-tokenSentry.io Organization Tokensntrys_eyJpYXQiO<10-200 chars>LCJyZWdpb25fdXJs<10-200 chars>_<43 chars>
sentry-user-tokenSentry.io User Tokensntryu_<64 chars>
settlemint-application-access-tokenSettlemint Application Access Tokensm_aat_****************
settlemint-personal-access-tokenSettlemint Personal Access Tokensm_pat_****************
settlemint-service-access-tokenSettlemint Service Access Tokensm_sat_****************
sidekiq-secretSidekiq Secret (Enterprise/Gems Bundle Auth)********:********
sidekiq-sensitive-urlSidekiq sensitive URLredis://<username>:<password>@<host>:<port>
snyk-api-tokenSnyk API token********-****-****-****-************
sslmate-api-keySSLMate API key************************************
sumologic-access-idSumoLogic Access IDsu************
sumologic-access-tokenSumoLogic Access Token<64 chars>
typeform-api-tokenTypeform API tokentfp_<59 chars>
unkey-root-keyUnkey root keyunkey_<20-32 chars>
wakatime-api-keyWakaTime API keywaka_<36-64 chars>
workato-developer-api-tokenWorkato developer API tokenwrka<0-2 chars>-eyJ<8+ chars>.<16+ chars>.<64+ chars>
workos-production-api-keyWorkOS production API keysk_live_a2V5Xz<69 chars>
zuplo-consumer-api-keyZuplo consumer API keyzpka_********************************_********
Payments, fintech & identity verification
Secret Type (Rule ID)DescriptionExample Format
asaas-api-tokenAsaas API token$aact_prod_<20-100 chars>
bittrex-access-keyBittrex Access Key********************************
bittrex-secret-keyBittrex Secret Key********************************
checkout-secret-keyCheckout.com secret keysk_********-****-****-****-************
coinbase-access-tokenCoinbase Access Token<64 chars>
duffel-api-tokenDuffel API tokenduffel_live_<43 chars>
finicity-api-tokenFinicity API token********************************
finicity-client-secretFinicity Client Secret********************
finnhub-access-tokenFinnhub Access Token********************
flutterwave-encryption-keyFlutterwave Encryption Key (Test)FLWSECK_TEST-************
flutterwave-public-keyFlutterwave Public Key (Test)FLWPUBK_TEST-********************************-X
flutterwave-secret-keyFlutterwave Secret Key (Test)FLWSECK_TEST-********************************-X
freshbooks-access-tokenFreshbooks Access Token<64 chars>
gocardless-api-tokenGoCardless API tokenlive_****************************************
gumroad-access-tokenGumroad access token<64 chars>
highnote-secret-live-keyHighnote live secret keysk_live_a2V5Xz<69 chars>
kraken-access-tokenKraken Access Token<80-90 chars>
kucoin-access-tokenKucoin Access Token************************
kucoin-secret-keyKucoin Secret Key********-****-****-****-************
mercury-production-api-tokenMercury production API tokenmercury_production_<3-6 chars>_<40-50 chars>_yrucrem
midtrans-production-server-client-keyMidtrans production server client keyMid-server-<10-20 chars>
onfido-live-api-token-caOnfido live API token CAapi_live_ca.<20-80 chars>
onfido-live-api-token-euOnfido live API token EUapi_live.<20-80 chars>
onfido-live-api-token-usOnfido live API token USapi_live_us.<20-80 chars>
paddle-live-api-keyPaddle live API keypdl_live_apikey_**************************_**********************_***
persona-production-api-keyPersona production API keypersona_production_<20-80 chars>
plaid-api-tokenPlaid API Tokenaccess-development-********-****-****-****-************
plaid-client-idPlaid Client ID************************
plaid-secret-keyPlaid Secret key******************************
polar-oauth-access-tokenPolar OAuth access tokenpolar_at_<20-100 chars>
polar-organization-access-tokenPolar organization access tokenpolar_oat_<20-100 chars>
polar-personal-access-tokenPolar personal access tokenpolar_pat_<20-100 chars>
polymarket-addressPolymarket wallet address0x****************************************
polymarket-api-keyPolymarket API key********-****-****-****-************
polymarket-api-secretPolymarket API secret<40+ chars>
polymarket-passphrasePolymarket passphrase<8-128 chars>
polymarket-private-keyPolymarket private key0x<64 chars>
rainforest-pay-production-api-keyRainforest Pay production API keyapikey_<64 chars>
ramp-client-idRamp client IDramp_id_****************************************
ramp-client-secretRamp client secretramp_sec_<48 chars>
square-access-tokenSquare Access TokenEAAA<22-60 chars>
stripe-access-tokenStripe API Key (Secret or Restricted)sk_live_<10-99 chars>
Communication, collaboration & productivity
Secret Type (Rule ID)DescriptionExample Format
asana-client-idAsana Client ID****************
asana-client-secretAsana Client Secret********************************
box-api-access-tokenBox API access token********************************
canva-client-idCanva client IDOC-<8-16 chars>
canva-client-secretCanva client secretcnvca<51 chars>
clickup-personal-api-tokenClickUp personal API tokenpk_<8-9 chars>_********************************
discord-api-tokenDiscord API Key<64 chars>
discord-client-idDiscord client ID******************
discord-client-secretDiscord client secret********************************
figma-personal-access-header-tokenFigma personal access header token****-********-****-****-****-************
figma-personal-access-tokenFigma personal access tokenfigd_<38-42 chars>
gitter-access-tokenGitter Access Token****************************************
intercom-api-keyIntercom API Token<60 chars>
lark-app-idLark app IDcli_****************
lark-app-secretLark app secret********************************
mailchimp-api-keyMailchimp API key********************************-us**
mailersend-api-tokenMailerSend API tokenmlsn.<30-100 chars>
mailgun-private-api-tokenMailgun private API tokenkey-********************************
mailgun-pub-keyMailgun public validation keypubkey-********************************
mailgun-signing-keyMailgun webhook signing key********************************-********-********
mattermost-access-tokenMattermost Access Token**************************
messagebird-api-tokenMessageBird API token*************************
messagebird-client-idMessageBird client ID********-****-****-****-************
microsoft-teams-webhookMicrosoft Teams Webhook URLhttps://<tenant>.webhook.office.com/webhookb2/<uuid>@<uuid>/IncomingWebhook/<32 chars>/<uuid>
notion-api-tokenNotion API tokenntn_<46 chars>
onesignal-rich-authentication-tokenOneSignal rich authentication tokenos_v2_app_<103 chars>
plivo-auth-idPlivo auth IDMA******************
plivo-auth-tokenPlivo auth token****************************************
sendbird-access-idSendbird Access ID********-****-****-****-************
sendbird-access-tokenSendbird Access Token****************************************
sendgrid-api-tokenSendGrid API tokenSG.<66 chars>
sendinblue-api-tokenSendinblue API tokenxkeysib-<64 chars>-****************
slack-app-tokenSlack App-level tokenxapp-1-<app id>-<number>-<hash>
slack-bot-tokenSlack Bot tokenxoxb-<10-13 chars>-<10+ chars>
slack-config-access-tokenSlack Configuration access tokenxoxe*xox*-*-<163-166 chars>
slack-config-refresh-tokenSlack Configuration refresh tokenxoxe-*-<146 chars>
slack-legacy-bot-tokenSlack Legacy bot tokenxoxb-<8-14 chars>-<18-26 chars>
slack-legacy-tokenSlack Legacy token (Test)xoxp-<digits>-<digits>-<digits>-<hash>
slack-legacy-workspace-tokenSlack Legacy Workspace tokenxox*-<8-48 chars>
slack-session-cookieSlack session cookiexoxd-<100+ chars>
slack-session-tokenSlack session tokenxoxc-<9-15 chars>-<9-15 chars>-<9-15 chars>-<64 chars>
slack-user-tokenSlack User tokenxox*-<10-13 chars>-<10-13 chars>-<10-13 chars>-<28-34 chars>
slack-webhook-urlSlack webhook URLhooks*slack*com/services/<43-56 chars>
telegram-bot-api-tokenTelegram Bot API Token<5-16 chars>:A**********************************
telnyx-api-v2-keyTelnyx API v2 keyKEY<55 chars>
twilio-api-keyTwilio API Key SIDSK********************************
zendesk-secret-keyZendesk Secret Key****************************************
Marketing, analytics, commerce & consumer services
Secret Type (Rule ID)DescriptionExample Format
adobe-client-idAdobe OAuth Web Client ID********************************
adobe-client-secretAdobe Client Secretp8e-********************************
airtable-api-keyAirtable API Key*****************
airtable-oauth-tokenAirtable OAuth token<token id>.v1.<payload>.<signature>
airtable-personnal-access-tokenAirtable personal access tokenpat**************.<64 chars>
amplitude-secret-keyAmplitude secret key********************************
apify-api-tokenApify API tokenapify_api_<34-38 chars>
bitly-access-tokenBitly access token****************************************
canadian-digital-service-notify-api-keyCanadian Digital Service Notify API keyApiKey-v1_gcntfy-<name>-<uuid>-<uuid>
cisco-meraki-api-keyCisco Meraki API Key****************************************
cloudinary-api-keyCloudinary API key***************
cloudinary-api-secretCloudinary API secret********************************
cloudinary-cloud-nameCloudinary cloud name<3-32 chars>
confluent-access-tokenConfluent Access Token****************
confluent-secret-keyConfluent Secret Key<64 chars>
contentful-delivery-api-tokenContentful delivery API token<43 chars>
disqus-api-keyDisqus API key<64 chars>
dropbox-api-tokenDropbox API secret***************
dropbox-long-lived-api-tokenDropbox long-lived API token***********AAAAAAAAAA<43 chars>
dropbox-short-lived-api-tokenDropbox short-lived API tokensl.<135 chars>
easypost-api-tokenEasyPost API tokenEZAK<54 chars>
easypost-test-api-tokenEasyPost test API tokenEZTK<54 chars>
ebay-client-ideBay client ID<app name>-<id>-PRD-<8-12 chars>-<8-12 chars>
ebay-client-secreteBay client secretPRD-********-****-****-****-<4-12 chars>
etsy-open-api-keyEtsy Open API key************************:<10-64 chars>
facebook-access-tokenFacebook Access Token (Legacy)<15-16 chars>|<27-40 chars>
facebook-page-access-tokenFacebook Page Access TokenEAA<101+ chars>
facebook-secretFacebook Application secret********************************
flickr-access-tokenFlickr Access Token********************************
fullstory-api-keyFullStory API keyna1.<20+ chars>
hubspot-api-keyHubSpot API Token********-****-****-****-************
intra42-client-secretIntra42 client secrets-s4t2ud-<64 chars>
klaviyo-api-keyKlaviyo API keypk_**********************************
lichess-personal-access-tokenLichess personal access tokenlip_<16-60 chars>
linkedin-client-idLinkedIn Client ID**************
linkedin-client-secretLinkedIn Client secret****************
lob-api-keyLob API Key (Live or Test)live_***********************************
lob-pub-api-keyLob Publishable API Key (Live or Test)live_pub_*******************************
looker-client-idLooker client ID********************
looker-client-secretLooker client secret************************
mapbox-api-tokenMapBox API tokenpk.<60 chars>.**********************
maxmind-license-keyMaxMind license key******_*****************************_mmk
nytimes-access-tokenNytimes Access Token********************************
openweather-api-keyOpenWeather API key********************************
pinterest-access-tokenPinterest access tokenpina_<20-200 chars>
posthog-personal-api-keyPostHog personal API keyphx_<41-49 chars>
posthog-project-api-keyPostHog project API keyphc_<41-44 chars>
salesforce-access-tokenSalesforce access token00*************!<80-260 chars>
salesforce-instance-urlSalesforce instance URL<instance>.my.salesforce.com
samsara-api-tokenSamsara API tokensamsara_api_<26-32 chars>
segment-public-api-tokenSegment public API tokensgp_<64 chars>
shippo-api-tokenShippo API token (Live or Test)shippo_live_****************************************
shopify-access-tokenShopify Admin API Access Tokenshpat_********************************
shopify-custom-access-tokenShopify custom access tokenshpca_********************************
shopify-private-app-access-tokenShopify private app access tokenshppa_********************************
shopify-shared-secretShopify shared secretshpss_********************************
squarespace-access-tokenSquarespace Access Token********-****-****-****-************
tableau-personal-access-tokenTableau personal access token**********************==:********************************
tableau-personal-access-token-nameTableau personal access token name<3-51 chars>
tableau-server-hostTableau server host<site>.online.tableau.com
twitch-api-tokenTwitch API token******************************
twitter-access-secretTwitter Access Secret<45 chars>
twitter-access-tokenTwitter Access Token<15-25 chars>-<20-40 chars>
twitter-api-keyTwitter API Key (Consumer Key)*************************
twitter-api-secretTwitter API Secret (Consumer Secret)<50 chars>
twitter-bearer-tokenTwitter Bearer TokenAAA<80-100 chars>
weatherstack-api-keyWeatherstack API key********************************
yandex-access-tokenYandex Access Tokent1.<segment>.<86-88 chars>
yandex-api-keyYandex API KeyAQVN<35-38 chars>
yandex-aws-access-tokenYandex AWS Access TokenYC**************************************
Cryptographic keys & generic credentials
Secret Type (Rule ID)DescriptionExample Format
age-secret-keyAge encryption tool secret keyAGE-SECRET-KEY-1<58 chars>
pkcs12-filePKCS#12 keystore file<filename>.p12 or <filename>.pfx
private-keyGeneric Private Key-----BEGIN PRIVATE KEY-----<base64 key material>-----END PRIVATE KEY-----
Types that never appear in results

Three of the types listed above are accepted by the type parameter but cannot currently be returned, so a query filtered to them will always come back empty:

  • azure-client-id — the detection rule is disabled. It matched any UUID sitting near a client_id keyword, which produced too many false positives in infostealer logs. It exists only as a helper for validating Azure service principals, never as a standalone finding.
  • generic-service-json — every match is re-validated as a GCP service account. It is either promoted to gcp-service-account-json or discarded, so it is never stored under its own type.
  • gcp-cloud-storage-interoperability-access-key — matches are logged for investigation but deliberately not stored.

One further type is conditional: aws-secret-key is only stored when an aws-access-token is found in the same source file, because a bare 40-character string cannot reliably be told apart from other Base64 data.

System Information

Details about the infected device:

  • OS version
  • IP address
  • Hardware information (HWID, Machine ID)
  • System language and settings

User Information

Personal details of the victim:

  • Device Username
  • Full name (if available)
  • Location (derived from IP)

Stolen Files

Documents, source code, configuration files, and other sensitive files exfiltrated from the device:

  • Personal documents
  • Financial records
  • Business information
  • Source code repositories
  • Configuration files (.env, .aws/credentials, etc.)

Data Example

Below is the Secrets tab of a Redline infection, alongside the counts of credentials, cookies, autofills and other artefacts recovered from the same device:

Secrets detected in a Redline malware infection

Each row pairs a rule ID from the Detected Secret Types tables with the recovered value. This infection yielded five values across four types: a Groq API key, two OpenAI project keys, a Stripe key, and a MongoDB connection string. The sidebar counts secrets by type, which is why it reads four while the table lists five rows.

Security Implications

Malware infection data presents unique and severe threats:

  • Immediate Risk: Credentials and cookies are often current and immediately usable for account takeover.
  • Session Hijacking: Stolen cookies can allow account access without credentials, bypassing MFA.
  • Multiple Service Exposure: A single infection can compromise dozens of services used by one individual.
  • Corporate Network Access: Infected employee devices may expose enterprise credentials, VPN keys, or internal service tokens.
  • Infrastructure Compromise: Leaked secrets (API keys, private keys, service tokens) found in files can grant attackers direct access to cloud environments, databases, code repositories, and other critical infrastructure, potentially leading to widespread breaches or system manipulation.
  • Source Code Exposure: Stolen source code can reveal proprietary algorithms or further vulnerabilities.

API Access Methods

The NordStellar Dark Web API provides multiple ways to access malware infection information, including detected secrets:

Direct Lookups

  • Query for specific email addresses using the /email/{email-sha256}/malware-logs endpoint.
  • Query for specific phone numbers using the /phone/{phone-sha256}/malware-logs endpoint.
  • Get detailed malware log information, including the secret array containing detected secret types and values, using the /data-source/malware-log/{id} endpoint.

Bulk Operations

  • Check multiple email addresses in a single request using the /email/malware-logs (POST) endpoint.
  • Check multiple phone numbers in a single request using the /phone/malware-logs (POST) endpoint.
  • Retrieve information about multiple malware logs using the /data-source/malware-log (POST) endpoint.
  • Retrieve metadata only, without the full stolen-data payload, using the /data-source/malware-log/details (POST) endpoint.
  • Retrieve per-log counts using the /data-source/malware-log/stats (POST) endpoint.

Secret Lookups

Secrets are returned inside the secret array of the full malware log, and dedicated endpoints also let you query them directly without retrieving the entire log:

  • Find the IDs of malware logs containing any secret using the /data-source/malware-log/secrets/type/id endpoint.
  • Find the IDs of malware logs containing a specific secret type using the /data-source/malware-log/secrets/type/{type}/id endpoint.
  • Retrieve all secrets from a single malware log using the /data-source/malware-log/{id}/secrets/type endpoint.
  • Retrieve secrets of a specific type from a single malware log using the /data-source/malware-log/{id}/secrets/type/{type} endpoint.
  • Page through secrets across many logs using the /data-source/malware-log/secrets/feed (POST) endpoint.

The {type} path parameter accepts any of the rule IDs listed under Detected Secret Types.

Specialized Queries

  • Search for credentials associated with specific URLs using the /data-source/malware-log/credentials/url/{credentials_url}/id endpoint.
  • Retrieve specific credential details using the /data-source/malware-log/{id}/credentials/url/{credentials_url} endpoint.
  • Page through credentials across many logs using the /data-source/malware-log/credentials/feed (POST) endpoint.

Trimming Large Responses

Malware logs can be very large. The endpoints that return full log data accept two mutually exclusive query parameters to control the payload:

  • inclusive-projection returns only the listed fields, for example ?inclusive-projection=credentials,secrets.
  • exclusive-projection returns everything except the listed fields, for example ?exclusive-projection=cookies,grabbed_files.

Both accept a comma-separated list or repeated parameters. The id field is always returned and cannot be excluded.

Use Cases

Account Protection

  • Identify and lock down compromised user accounts based on stolen credentials.
  • Force password resets for affected services.
  • Invalidate stolen browser cookies to prevent session hijacking.

Infrastructure Security & Secret Management

  • Detect Exposed Secrets: Monitor malware logs for leaked API keys, tokens, or private keys related to your corporate infrastructure (e.g., AWS keys, GitHub tokens found on developer machines).
  • Rapid Revocation: Immediately revoke compromised secrets identified in malware logs to prevent unauthorized access.
  • Improve Secret Hygiene: Use findings as indicators of poor secret management practices (e.g., hardcoding secrets in source code found on infected devices).

Threat Intelligence

  • Gain insights into active malware campaigns targeting specific services or user groups.
  • Identify targeted organizations and the types of credentials or secrets attackers are harvesting.
  • Understand the capabilities and targets of different infostealer variants.

Incident Response

  • Determine the scope of a malware infection by identifying all affected accounts, services, and potentially exposed secrets.
  • Assess the potential damage from stolen credentials, cookies, and secrets.
  • Prioritize remediation based on the sensitivity of exposed data and secrets.

Corporate Security

  • Monitor for corporate credential and secret exposure from employee device infections.
  • Identify infected devices that may have access to corporate resources or codebases containing secrets.
  • Detect breached VPN, cloud service, internal system credentials, or API keys.

By leveraging malware infection data, including the critical aspect of leaked secrets, through the NordStellar Dark Web API, organizations can rapidly respond to active threats, protect user accounts and infrastructure, and gain valuable intelligence about the evolving threat landscape.

NordStellar © 2026Privacy Policy