Commodity Infostealers Harvest AI Agent Credentials at Scale: Gen Digital Maps the Families, Okta Counts Replayable Tokens Fueling LLMjacking, and OpenAI Unveils an Agent 'Defense…
Three strands reported September 9-10, 2026: Gen Digital documents commodity infostealers (Amatera, Remus, CallbackBeaver, Djinn Stealer) stealing Claude, Cursor and Codex agent tokens, prompt histories and MCP configs via remotely managed collection rules;…
The story spans the full arc of AI-agent credential abuse — theft, monetization, and defense. On the theft side, Gen Digital researchers found commodity infostealers extending their collection rules to local AI coding agent data from Claude, Cursor, Codex, Cline, Continue and OpenCode on Windows and macOS. Targeting breaks down as: Amatera against Cline and Continue; Remus against Claude, Cursor and OpenCode (assessed as a Lumma Stealer variant using EtherHiding C2 resolution via Ethereum smart contracts); CallbackBeaver, which added Claude and Cursor to its scope with more than 5,000 samples observed in 30 days; and macOS-focused Djinn Stealer against Claude, Codex, Gemini, Cline, OpenCode and Kilo. Stolen data includes access and refresh tokens, prompt histories, conversation databases and MCP configuration files holding API keys, potentially exposing connected source-control, cloud, database and ticketing systems. Amatera and Remus detections were recorded among tens of thousands of protected users — Cyber Security News specifies protected Windows users over a three-month window — and both reports stress these are detections, not confirmed infections, and that remotely managed collection rules mean an adaptation of existing infostealers via config updates rather than a new vulnerability in the AI tools themselves. On the monetization side, Okta analyzed a 7 GB infostealer dump dated August 2, 2026 covering 5,871 infected machines in 162 countries: 555 of 44,791 JWTs related to AI services, 1,843 unexpired JWTs and JWEs (largely set by OpenAI via NextAuth.js), 24 still-valid API keys for Google Gemini, OpenAI, Groq and OpenRouter, and 17.7% of JWTs containing plaintext PII usable for social engineering. Valid sessions and keys can be replayed with anti-detect browsers like Camoufox to bypass credential, MFA and impossible-travel checks, feeding an underground market for AI account access known as LLMjacking, where attackers run up victims' AI compute bills for espionage, extortion or resource theft. Google's GTIG reported growing buyer demand for Claude, Gemini, Cursor and Devin credentials, and Mandiant handled an incident where an actor used an exposed GitHub PAT to deploy unauthorized AI infrastructure and scale high-performance compute. On the defense side, OpenAI introduced a Defense Factory, an agent-first cybersecurity operation connecting AI agents to GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear and ServiceNow via APIs, CLIs and Model…
- Gen Digital: infostealer targeting by family — Amatera hits Cline and Continue; Remus hits Claude, Cursor and OpenCode; CallbackBeaver added Claude and Cursor with more than 5,000 samples observed in 30 days; macOS-focused Djinn Stealer…
- Remus is assessed as a Lumma Stealer variant using EtherHiding C2 resolution via Ethereum smart contracts.
- Amatera and Remus detections were recorded among tens of thousands of protected users; Cyber Security News specifies protected Windows users over a three-month window; the reports stress detections, not confirmed infections.
- Collection rules are remotely managed, letting criminals add new agent targets via config updates — an adaptation of existing infostealers, not a new vulnerability in the AI tools.
- Okta analyzed a 7 GB infostealer dump dated August 2, 2026 covering 5,871 infected machines in 162 countries.
- Of 44,791 JWTs in the dump, 555 related to AI services; 1,843 JWTs/JWEs were unexpired (largely set by OpenAI via NextAuth.js); 24 API keys for Google Gemini, OpenAI, Groq and OpenRouter were still valid; 17.7% of JWTs contained plaintext…
- Stolen session tokens and API keys can be replayed with anti-detect browsers such as Camoufox to bypass credential, MFA and impossible-travel checks, fueling the LLMjacking underground market for AI account access.
- Google's GTIG reported growing buyer demand for Claude, Gemini, Cursor and Devin credentials; Mandiant handled an incident where an exposed GitHub PAT was used to deploy unauthorized AI infrastructure and scale high-performance compute.
Coverage timelineoldest first · each row is one article
- · 6d agoInfostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data
GBHackers· 62
Gen Digital researchers report infostealer families Amatera, Remus and CallbackBeaver now harvest Claude, Cursor and Codex agent data, including tokens and MCP configs.
- · 6d agoHackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories
Cyber Security News· 58
Gen Digital found infostealers like Amatera and Remus stealing AI coding agent tokens, prompt histories, and MCP configs from infected Windows and macOS machines.
- · 6d agoInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
The Hacker News· 60
Okta finds infostealer logs contain thousands of replayable AI session tokens and API keys, letting criminals bypass MFA and access services from Google, Anthropic and OpenAI.
- · 5d agoOpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities
Cyber Security News· 55
OpenAI unveils a Defense Factory where AI agents continuously discover, validate, and fix vulnerabilities, integrating GitHub, Snyk, Semgrep, Tenable, and ServiceNow.