file_path

%TEMP%\browser-extraction-<username>

discovered 2026-06-01

Staging directory for injected browser credential data. <username> replaced with victim's Windows username.