ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Infostealers Harvest AI Agent Tokens and Prompt Histories From Claude, Cursor, Codex and Other AI Tools, Enabling MFA-Bypassing Replay Attacks

mediumThreat actorexploited in the wildimportance 60
What's new: This is the first merged summary for this story. Key developments: AI-focused infostealers are expanding their collection scopes via remotely managed rules (CallbackBeaver recently added Cursor and Claude, with more than 5,000 samples in 30 days), and Okta's analysis of a single August 2, 2026 dump quantified the exposure (555 of 44,791 JWTs tied to AI services, 1,843 unexpired JWTs/JWEs, and 24…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Gen Digital observed infostealers such as Amatera, Remus, CallbackBeaver and macOS-focused Djinn Stealer stealing AI coding agent tokens, prompt histories and MCP configs from infected Windows and macOS machines, while Okta found thousands of replayable AI…

Gen Digital analysts observed Amatera and Remus infostealer detections among tens of thousands of protected Windows users over three months, with Amatera targeting Cline and Continue data and Remus targeting Claude, Cursor, and OpenCode. CallbackBeaver added Cursor and Claude to its collection scope with more than 5,000 samples in 30 days, while macOS-focused Djinn Stealer has been associated with Claude, Codex, Gemini, Cline, OpenCode, and Kilo. The stealers harvest access and refresh tokens, prompt histories, and MCP configuration files that can expose source control, ticketing, databases, cloud resources, and sensitive project context for follow-on fraud. Many stealers add targets via remotely managed rules, meaning this is an adaptation of existing infostealers rather than a new vulnerability in the AI tools themselves. In a parallel analysis, Okta examined a 7 GB infostealer dump from August 2, 2026 covering 5,871 infected machines in 162 countries and found 555 of 44,791 JWTs tied to AI services, 1,843 unexpired JWTs and JWEs (largely set by OpenAI via NextAuth.js), and 24 still-valid API keys for Google Gemini, OpenAI, Groq, and OpenRouter. Valid session tokens and API keys can be replayed with anti-detect browsers like Camoufox to bypass credential and MFA checks, fueling an underground market for AI account access known as LLMjacking, where attackers rack up victims' AI compute bills; 17.7% of the JWTs contained plaintext PII usable for social engineering. Google's GTIG reported growing buyer demand for Claude, Gemini, Cursor, and Devin credentials, and Mandiant handled an incident where an actor used an exposed GitHub PAT to deploy unauthorized AI infrastructure and scale high-performance compute. Responders should revoke AI sessions and rotate API keys from a clean device, noting that MFA may not prevent replay of tokens already copied by malware.

  • Gen Digital observed Amatera and Remus detections among tens of thousands of protected Windows users over three months; Amatera targets Cline and Continue data, and Remus targets Claude, Cursor, and OpenCode.
  • CallbackBeaver added Cursor and Claude to its collection scope with more than 5,000 samples in 30 days; macOS-focused Djinn Stealer is associated with Claude, Codex, Gemini, Cline, OpenCode, and Kilo.
  • The stealers harvest access and refresh tokens, prompt histories, and MCP configuration files that can expose source control, ticketing, databases, cloud resources, and sensitive project context for follow-on fraud.
  • Stolen access and refresh tokens enable paid API abuse and resale of account access; MCP configs may leak API keys exposing source control, databases, and cloud services.
  • Okta analyzed a 7 GB infostealer dump from August 2, 2026 covering 5,871 infected machines in 162 countries.
  • 555 of 44,791 stolen JWTs were tied to AI services; the dump also contained 1,843 unexpired JWTs and JWEs (largely set by OpenAI via NextAuth.js) and 24 still-valid API keys for Google Gemini, OpenAI, Groq, and OpenRouter.
  • Valid session tokens and API keys can be replayed with anti-detect browsers such as Camoufox to bypass credential, MFA, and impossible-travel checks, fueling a market known as LLMjacking in which stolen API keys are used for espionage,…
  • 17.7% of the JWTs in the Okta dataset contained plaintext PII usable for social engineering.

Coverage timeline

  1. · 7d ago
    Cyber Security News· 58
    Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

    Gen Digital found infostealers like Amatera and Remus stealing AI coding agent tokens, prompt histories, and MCP configs from infected Windows and macOS machines.