Xavier_Ulp Stealer Log Exposes 254,318 Emails and Passwords
HEROIC's monitoring picked up yet another Xavier_Ulp stealer log on Telegram, dated May 19, 2026, this one holding 254,318 records. Three Xavier_Group leaks in a matter of weeks paints a pretty clear picture of an infostealer campaign that hasn't slowed down.
Why This Is Dangerous
Each of these records ties an email address to a plaintext password and the exact website it was used on. There's no need for an attacker to crack a hash or run a brute force attack, the login is handed to them ready to use. That's what separates stealer logs from most other types of breaches people hear about.
What Was Exposed
- 254,318 individual records
- Email Addresses
- Plaintext Password
- URLs for each saved login
Why This Matters
If you recognize any part of your own login habits in this description, its worth pausing. Repeated leaks from the same malware family often mean the same devices keep getting reinfected, wich means one cleanup isn't always enough to stop the bleeding.
How Stealer Logs Work
Infostealer malware like this typically arrives disguised as a cracked app, a fake invoice attachment, or a "free" tool downloaded from an untrusted site. Once it runs, it reads through the browser's stored password vault, grabs saved cookies and autofill entries, and quietly uploads everything to a server the attacker controls. The result is a tidy file, like this 254,318 record dump, ready to recieve buyers on dark web forums or Telegram channels.
Check If You Are Affected
Don't wait to find out the hard way. HEROIC's free breach scanner checks your email against more than 400 billion leaked records. Its definately worth the thirty seconds it takes to run a search and see which, if any, of your accounts show up.
Breach Breakdown
254,318 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds