Skip to content
Threat Feed
medium advisory

Detection of Python-Based Credential Theft on macOS

This brief details a detection strategy for identifying post-exploitation credential theft where Python processes access sensitive files such as SSH keys, keychain databases, and browser cookies for the first time on a macOS host.

This threat detection brief focuses on identifying the first-time access of sensitive credential files by Python processes on macOS hosts. Attackers often leverage Python in post-exploitation scenarios, utilizing malicious scripts, supply-chain compromised dependencies, or insecure deserialization primitives like Python's pickle or PyTorch model file loading (__reduce__) to execute arbitrary code. Once code execution is achieved, adversaries target sensitive files to facilitate lateral movement, cloud environment escalation, or session hijacking.

Legitimate system Python processes or standardized automation tools typically have predictable file access patterns. When a Python process initiates an open event on sensitive targets - such as ~/.ssh/id_rsa, macOS keychain databases, or browser cookie stores - for the first time on a specific host, it serves as a high-fidelity indicator of potential credential theft. Defenders should prioritize alerting on these unique file access events to intercept exfiltration or further attacker movement.

Impact

Successful exploitation allows attackers to gain persistence and broader access to the victim's environment by stealing highly sensitive credentials. Compromised assets may include cloud provider access keys (AWS/GCP), SSH private keys for lateral movement, Kerberos tickets (ccache files), and browser session cookies. If these credentials are exfiltrated, attackers can bypass multi-factor authentication, gain unauthorized access to cloud management consoles, or pivot into other systems within the organization, leading to data breaches and deep network penetration.

Recommendation

Prioritize the implementation of behavioral monitoring that tracks the first access of sensitive files by non-standard processes.

  • Deploy detection logic to alert on the first-time access of known sensitive credential file paths by any process named python*.
  • Investigate the process lineage and command-line arguments of any Python process triggering this alert to determine if the activity stems from legitimate automation or malicious execution.
  • Implement weights_only=True enforcement for all PyTorch model loading operations in the environment to mitigate risks associated with deserialization attacks.
  • Audit and rotate credentials (SSH keys, cloud tokens) associated with the host if the Python process access is confirmed as unauthorized.
  • Establish a baseline of known-good Python-based management tools to reduce noise from administrative workflows.

Immediate actions

Deploy rule to identify first-time Python access to sensitive files.

Detection Engineering 48h

Threat Hunt

Search for historical Python access to sensitive directories.

T1552 medium medium confidence hunt now

Data: file_event

Mitigations

Enforce weights_only=True in PyTorch model loading.

short_term Data Science Team

Deserialization attacks

Detection coverage 1

Detect First Time Python Access to Sensitive Files

medium

Detects the first time a Python process accesses sensitive credential files on a macOS host, which may indicate post-exploitation activity or credential theft.

sigma tactics: credential_access techniques: T1552.001, T1555.001 sources: file_event, macos

Detection queries are available on the platform. Get full rules →