Checking a Device for Password-Stealing Malware
Infostealer malware grabs saved passwords, browser sessions and crypto wallets. How it gets onto devices, signs of infection, and a clean-up plan that includes changing passwords from a safe device.

If your accounts keep getting taken over even after you change passwords, or several accounts were compromised at once, the cause may be on your own device. Password-stealing malware, often called an infostealer, quietly collects saved passwords, browser sessions and more, and sends them to criminals.
What infostealers take
- Passwords saved in browsers
- Browser cookies and sessions, which can let attackers use your logged-in accounts
- Autofill data such as addresses and cards
- Crypto wallet files and extensions
- Screenshots and files
How it gets in
- Pirated software, "cracks" and keygens
- Fake game mods and cheats
- Fake software updates and malicious adverts
- Email attachments and links
- Fake apps and browser extensions. See fake apps.
Signs of infection
- Several accounts compromised around the same time.
- Accounts taken over again soon after changing passwords.
- Sessions or logins from unknown devices despite two-step verification.
- New browser extensions or programs you did not install.
- Security software disabled.
Do not change passwords from an infected device. The malware may capture them again. Clean the device first, or use another trusted device.
Clean-up plan
- Disconnect the device from the internet.
- From a clean device, change your most important passwords in the right order and sign out of all sessions. See password change order.
- Scan the infected device with reputable security software, and remove suspicious programs and extensions.
- If in doubt, reset the device: back up personal files (not programs), then reinstall the operating system.
- Move crypto to a new wallet from a clean device if wallet data may have been stolen.
- Review accounts for changes, new devices and forwarding rules.
Prevention
- Install software only from official sources.
- Keep your system and browser updated.
- Use a password manager with a strong main password rather than relying only on browser storage.
- Prefer passkeys where available.
Unsure about a download link? Paste it into CyberWatch AI Scan for a free check before opening it.
For more on malware, see our malware and ransomware guide. For account recovery, see how to recover a taken-over account.
Frequently asked questions
What is an infostealer?
Malware designed to collect saved passwords, browser cookies and sessions, autofill data, crypto wallets and other information, and send it to criminals.
How does it get on a device?
Commonly through pirated software, fake game cheats or cracks, malicious ads, fake updates, email attachments and fake apps.
Can two-step verification protect me?
It helps, but some infostealers steal session cookies that keep you logged in. That is why signing out of all sessions after an infection matters.
Sources
- Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission
- Mitigating malware and ransomware attacks, UK National Cyber Security Centre
- Recovering a hacked account, UK National Cyber Security Centre


