Browser credential theft followed by exfil to /api/v1/ext/passwords C2 endpoint
Detects a process reading credential store files (Login Data) from multiple Chromium-based browsers, immediately followed by an HTTP POST request to a specific exfiltration endpoint associated with the Psychedelic Stealer malware.
YARA-L

