Free tools Windows power users keep installed
One-click scans. No signup required.
TIKTOUK is a credential-collection toolkit described by LevelBlue SpiderLabs on October 1, 2026. Its reported components probe WordPress sites, collect exposed configuration and option data, recover certain encrypted SMTP settings when the corresponding keys are available, and scan JavaScript for secret-like strings. The analysis demonstrates those component behaviors in a controlled setup; it does not establish that either of two associated vulnerabilities was successfully exploited or that any particular site was breached.
What the TIKTOUK toolkit does
Maor Gabay’s October 1, 2026 LevelBlue SpiderLabs analysis describes three components that obtain tasks from a central HTTP hub and send results or status information back to it:
| Component | Reported role |
|---|---|
wp2s_poll.py |
Probes WordPress sites. |
wp2s_crack.py |
Collects exposed configuration and WordPress option data, then processes credentials and settings. |
jscrawl-amd64 |
A Go-compiled Linux crawler that retrieves referenced JavaScript and scans it for secret-like patterns. |
The report’s controlled executions used synthetic target data and an analyst-controlled hub. They show how the components behave, but do not prove a live-site compromise or establish that all components are automatically handed off to one another.
How it could collect SMTP, AWS and API credentials
Exposed files and WordPress data
The collection script reportedly requested files that can expose configuration, environment variables, source-control settings, database backups, or debug information: wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log. It parsed returned configuration for database credentials and WordPress key material, and used nested REST batch requests to query database option values. The reported collected data included SMTP records, AWS credential pairs, and API-key patterns.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Encrypted SMTP settings
LevelBlue identified routines for settings associated with WP Mail SMTP, Easy WP SMTP, and FluentSMTP. The report says the toolkit used corresponding keys or WordPress configuration material when available to recover plaintext credentials. It does not say the toolkit broke those encryption algorithms. It also describes deriving an SES SMTP password from a supplied AWS secret.
Secrets in JavaScript
The Go crawler inspected page content and referenced scripts for secret-like strings. Returned findings described by LevelBlue included patterns for SendGrid, Anthropic, and Bedrock tokens, as well as AWS-shaped credential pairs. A pattern match is a lead to investigate, not by itself proof that a credential is valid or was used.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
What the CVE references do—and do not—show
The analysis connects some request structures to CVE-2026-60137, concerning insufficient sanitization of the author__not_in parameter in WP_Query, and CVE-2026-63030, concerning REST batch-route confusion that can combine with SQL injection for remote code execution. In the advisory context cited in the October 1 report, the affected version ranges were WordPress 6.9.x releases before 6.9.5 and 7.0.x releases before 7.0.2. These are time-sensitive version details, not a substitute for current WordPress vendor guidance.
Critically, LevelBlue says its analysis did not demonstrate successful exploitation of either CVE. Its target simulator returned prepared responses without executing SQL. The presence of related request structures therefore should not be represented as proof that TIKTOUK exploited those vulnerabilities to compromise a site.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
The separate CERT-EU advisory from January 19, 2024 concerned CVE-2023-6875 in the POST SMTP plugin, affecting versions through 2.8.7 and recommending 2.8.8 or later. That is historical context for a different vulnerability; the TIKTOUK analysis does not establish that the toolkit used it.
What LevelBlue reported about scale
LevelBlue analyst Leon Cottrell examined a leaked TIKTOUK panel. LevelBlue’s October 1, 2026 report says the panel displayed approximately 50,000 server-side credentials across approximately 37,000 domains, including hundreds of actor-validated live AWS keys with potential for SES, EC2, and Bedrock abuse. Those figures describe the panel contents as reported by LevelBlue; they are not independently audited counts of victims or confirmed compromises.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Separately, LevelBlue analyst Ben Lee supplied indicators from real-world incident telemetry. LevelBlue reported a victim host retrieving payloads from 31.56[.]58[.]59 and continuing to communicate with that controller, and said it was monitoring additional panels at 193.32.162[.]134 and 195.178.110[.]209. The report also identified a related Go-compiled botnet binary with remote-command-execution capability. These are dated, volatile indicators; verify them against current trusted threat intelligence before using them for blocking or attribution.
How to investigate whether a WordPress site was targeted
Do not treat a single path, parameter, endpoint, or hash match as conclusive. LevelBlue recommends correlating request sequences with the site’s own HTTP, application, and server records, particularly where requests for exposed data are followed by result submissions.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
- Review REST batch requests containing
http://:alongside nestedauthor_excludeorUNIONexpressions. A sequence in which JSON requests are followed by multipart requests deserves closer review. - Check for requests to the exposed configuration, backup, environment, and debug-file paths named above, then look for subsequent submissions consistent with the reported collection workflow.
- Treat
/v1/ingestand/api/crack/reportas contextual workflow indicators only; either path alone does not establish malicious activity. - Compare any recovered samples with the hashes below, and correlate matches with surrounding HTTP activity and local system records. Validate matches against current trusted intelligence before relying on them.
| Sample | Reported hash |
|---|---|
wp2s_poll.py (SHA-256) |
c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 |
wp2s_crack.py (SHA-256) |
0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 |
jscrawl-amd64 (SHA-256) |
1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 |
| Related botnet binary (SHA-1) | 9903f4576980ff7cfd560ca57c665a4b59b3c30d |
What to do if evidence points to exposure
First establish what was exposed and when using site logs, server records, and the affected software inventory. If records indicate a credential was disclosed, rotate that credential and review related services for unauthorized use; the report does not provide a universal rotation schedule for every collection path. Consult current WordPress and plugin vendor advisories for patch guidance rather than treating the CVE version context above as current remediation advice. Preserve relevant logs and samples if a forensic investigation may be needed.
LevelBlue’s findings are threat-analysis observations, not a vendor patch plan or proof that every site with a vulnerable version was targeted. A response should be based on correlated evidence and the scope of credentials that may have been exposed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




