YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]
- Category
- YARA Match
- Confidence
- 78% confidence
- Finding
This match is not evidence of malware or an information stealer by itself, but it does identify a genuinely sensitive behavior: accessing browser cookies to authenticate fallback downloads. In the context of an agent skill, encouraging cookie extraction without strong warnings or approval controls can expose session credentials and make the capability significantly more dangerous than ordinary transcript retrieval.
- Content
md d transcripts | | | `--exclude-manually-created` | Skip manually created transcripts | | | `--refresh` | Force re-fetch, ignore cached data | | | `-o, --output <path>` | Save to specific file path | auto-generated | | `--output-dir <dir>` | Base output directory | `youtube-transcript` | ## Optional Environment Variables | Variable | Description | |----------|-------------| | `YOUTUBE_TRANSCRIPT_COOKIES_FROM_BROWSER` | Passed to `yt-dlp --cookies-from-browser` during fallback, e.g. `chrome`, `safari`, `firefox`, or `chrome:Profile 1` | ## Input Formats Accepts any of these as video input: - Full URL: `https://www.youtube.com/watch?v=dQw4w9WgXcQ` - Short URL: `https://youtu.be/dQw4w9WgXcQ` - Embed URL: `https://www.youtube.com/embed/dQw4w9WgXcQ` - Shorts URL: `https://www.youtube.com/shorts/dQw4w9WgXcQ` - Video ID: `dQw4w9WgXcQ` ## Output Formats | Format | Extension | Description | |--------|-----------|-------------| | `text` | `.md` | Markdown with frontmatter (incl. `descriptio
