YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]
- Category
- YARA Match
- Confidence
- 84% confidence
- Finding
The matched string resembles info-stealer behavior because
--cookies-from-browser chromeaccesses browser-stored session cookies. In this specific skill the apparent purpose is functional access to bilibili subtitles rather than credential theft, but the mechanism is still security-sensitive: if an agent executes it automatically or exposes outputs, it could retrieve and mishandle live authenticated session data.- Content
��模型)
bash # 简单去时间轴与标记(按需调整路径) sed -e '/^WEBVTT/d' -e '/^NOTE/d' -e '/^[0-9][0-9]:/d' -e '/^$/d' -e 's/<[^>]*>//g' \ "某文件.zh-Hans.vtt" | sed '/^$/d' > bilibili_subtitles_plain.txt若出现 HTTP 412 / 无法下载网页
B 站可能对匿名请求限流。按顺序尝试:
-
用浏览器 Cookie(推荐)
bash yt-dlp --cookies-from-browser chrome --list-subs "URL"可将
chrome换成safari、firefox(本机需已登录 bilibili.com)。 -
导出 Netscape 格式 cookies.txt,再:
yt-dlp --cookies /path/to/cookies.txt ... -
升级 yt-dlp 后重试。
详见 reference.md。
对 Agent 的提示
- 先
--list-subs,无可用语言则明确告知用户「该 BV 无字幕轨」,不要假装已提取。 - 提取成功后,优先读
.srt/.vtt再总结;长文本可先落盘再分段阅读。 - 勿在回复中粘贴完整 Cookie 或账号秘密
-
