Security researchers at LevelBlue have pulled back the curtain on a credential-harvesting toolkit, internally named TIKTOUK, that turns an everyday WordPress mistake — leaving a site backup or configuration file sitting in a publicly reachable location — into a pipeline for stealing cloud and email credentials at scale. A leaked control panel used to run the operation revealed roughly 50,000 real, server-side credentials gathered from about 37,000 domains, including hundreds of AWS access keys that the researchers confirmed were still active.
Rather than relying on one single exploit, TIKTOUK bundles several different collection techniques together: scanning sites for exposed sensitive files, recovering stored passwords from plugin configurations, and scraping secrets out of JavaScript served to ordinary site visitors. LevelBlue says the operation was already running at meaningful scale by the time it was identified through a combination of source code review, reverse engineering, and controlled lab testing.
Inside the Toolkit’s Architecture
TIKTOUK is built from two Python components plus a Linux-based crawler written in Go, all of which check in with a central HTTP service to receive tasks and report back findings. The coordination layer distributes targets and collects results, though LevelBlue’s testing didn’t find evidence of a fully automatic handoff between the different components — suggesting a human operator may still be steering parts of the operation.
The probing component handles initial reconnaissance: it pulls a list of targets, confirms which ones are running WordPress, and then sends specially crafted REST API batch requests that combine a malformed URL with delete and content-rendering operations. When a request formatted as JSON gets rejected, the tool automatically retries using multipart encoding instead — and that retry frequently succeeds. That specific fallback pattern, LevelBlue notes, gives defenders a distinctive signature to hunt for in their own web server logs.
Turning a Backup File Into a Credential Dump
A separate collection module goes after exposed WordPress configuration backups directly, pulling database credentials and WordPress security keys out of them. It doesn’t stop there — the same component also probes for exposed environment files, repository configuration, raw database backups, and debug logs, essentially sweeping up anything left accessible through a plain web request that shouldn’t be.
Some of its database queries are notably methodical: nested batch requests first retrieve the name WordPress uses for its options table, then feed that name into follow-up queries designed to pull the option values themselves. The tool decodes hexadecimal-encoded responses back into readable text and assembles structured records containing database settings, stored email credentials, AWS key pairs, and recognizable API key patterns.
From Website Compromise to Cloud Takeover
The blast radius extends well past the compromised website itself. The leaked operator panel contained AWS keys with the potential to be abused for sending email, spinning up compute resources, or accessing AI services tied to the victim’s cloud account. TIKTOUK’s collector can specifically decrypt stored settings from popular SMTP plugins — WP Mail SMTP, Easy WP SMTP, and FluentSMTP — recovering plaintext email credentials using encryption keys or configuration material the tool already has access to. LevelBlue is careful to note this isn’t a cryptographic breakthrough; the toolkit simply gets its hands on what it needs to unlock settings that were never meant to be exposed in the first place. In one particularly efficient step, it can even derive an Amazon SES email password directly from a stolen AWS secret key.
A third piece, the JavaScript crawler, fetches site pages and any scripts they load, scanning the contents for credential patterns tied to services like SendGrid, Anthropic, AWS Bedrock, and AWS more broadly — all secrets that were likely embedded in client-side code by mistake and shipped straight to every visitor’s browser.
Exploitation Links and What’s Still Unconfirmed
LevelBlue connected TIKTOUK’s request patterns to two specific vulnerabilities, CVE-2026-60137 and CVE-2026-63030, which affect a batch-route mechanism in WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2. Importantly, the firm’s lab testing didn’t go as far as demonstrating a full working exploit — controlled test targets returned pre-prepared responses without actually executing attacker-supplied SQL. That said, separate incident telemetry did confirm the toolkit successfully retrieved payloads and communicated with its controller infrastructure in the wild, and investigators separately identified a related Go-based botnet capable of remote command execution.
In short: the lab results establish exactly how the components behave, not that a specific live production site has been fully breached end-to-end using this chain. Site operators shouldn’t read that distinction as reassuring, though, given the scale of credentials already found in the leaked panel.
What WordPress Site Owners Should Check
- Confirm backup files, configuration exports, and debug logs are never stored inside a publicly web-accessible directory.
- Update WordPress past the affected 6.9.x and 7.0.x ranges identified in the advisory.
- Rotate SMTP plugin credentials and any AWS keys that may have been referenced in configuration files or client-side JavaScript.
- Watch server logs for the JSON-then-multipart retry pattern on REST batch endpoints as a potential sign of probing activity.
- Audit JavaScript served to visitors for hard-coded API keys or secrets that should never have been placed there.
Leave a Reply
You must be logged in to post a comment.