MolverCloud 05.12.2022: How Your Browser Exposed 3,577 US Passwords
In December 2022, a stealer log identified as "MolverCloud 05.12.2022" was uploaded to Telegram, exposing 3,577 email addresses and plaintext passwords from US devices. The data came directly from browser credential stores: the built-in password manager that Chrome, Firefox, Edge, and other browsers use to save and autofill passwords. Every major browser offers to remember your passwords for convenience. That same convenience creates a single point of failure on your device that stealer malware is specifically designed to exploit.
How Browser-Saved Passwords Became the Target
Modern browsers store saved passwords in encrypted local files on your device. When you autofill a login, the browser decrypts that file using a key derived from your system credentials and fills in your username and password. Stealer malware targets this exact mechanism. Once installed on a device, it locates the browser credential database, decrypts it using the same system-level access the browser uses, and extracts every saved username, password, and associated URL in plaintext. It also captures active session cookies, which can bypass authentication entirely without needing the password. The entire process takes seconds and leaves no visible trace.
The result is a log file containing every site the browser has saved credentials for, paired with the URL that confirms the victim was actively using that service. For the 3,577 people in the MolverCloud 05.12.2022 log, all of their browser-stored passwords were extracted at once.
What Was Exposed in the MolverCloud 05.12.2022 Log
- Email Addresses: Login identifiers for the compromised accounts, sourced directly from saved browser credentials
- Plaintext Passwords: Decrypted credentials extracted from browser storage, immediately usable without any additional processing
- URLs: Every site the browser had credentials saved for, confirming exactly which services each victim used
Why This Matters: Browser Password Storage Is a High-Value Target
Browser credential stores are attractive targets because they consolidate many passwords in one location. A single infection can yield credentials for email, banking, shopping, social media, and work accounts in a single extraction. For attackers, this is far more efficient than targeting individual services. The 3,577 records in the MolverCloud log represent 3,577 device infections, each of which likely yielded credentials for multiple services in one pass.
This log was uploaded in December 2022. Any account in this log where the user has not changed their password since then remains accessible with those credentials today.
How Stealer Malware Reaches Devices
Stealer malware typically arrives through phishing emails, fake software downloads, malicious browser extensions, or compromised files shared through social media and messaging platforms. Once a user installs or runs the infected file, the malware activates silently, performs its extraction, and exits. The December 6, 2022 MolverCloud upload is the collected output of that process across infected US devices, compiled and posted to Telegram for open download.
Check If Your Email Appears in the MolverCloud 05.12.2022 Breach
HEROIC's breach database includes historical stealer logs going back years, covering more than 400 billion records. A free scan of your email address will show you whether your credentials appear in the MolverCloud 05.12.2022 log or any other tracked breach.
Run a free scan at HEROIC.com. If your address appears, change the affected password immediately, consider moving saved passwords out of your browser into a dedicated password manager, and enable two-factor authentication on all critical accounts.
Breach Breakdown
3,577 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds