Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Autonomous AI Agents Launch Mass Credential Theft Attacks
September 9, 2026
New Attack Steals Tokens, Prompt Histories From Claude, Cursor, Codex AI
September 9, 2026
ClickFix Uses Google Sheets to Hijack Crypto Wallets
September 9, 2026
Home/Threats/New Attack Steals Tokens, Prompt Histories From Claude, Cursor, Codex AI
Threats

New Attack Steals Tokens, Prompt Histories From Claude, Cursor, Codex AI

Key Takeaways Information-stealing malware is now targeting local data from AI coding agents like Claude, Cursor, and Codex. This activity does not indicate new vulnerabilities in the AI agents...

Sarah simpson
Sarah simpson
September 9, 2026 5 Min Read
3 0

Key Takeaways

  • Information-stealing malware is now targeting local data from AI coding agents like Claude, Cursor, and Codex.
  • This activity does not indicate new vulnerabilities in the AI agents themselves but rather criminals adapting existing infostealers to collect sensitive local files.
  • Stolen data can include access tokens, prompt histories, project records, and credentials for connected services, posing significant risks beyond individual account compromise.
  • Multiple infostealers, including Amatera, Remus, CallbackBeaver, and Djinn Stealer, have been observed incorporating AI agent data into their collection scope.
  • Organizations must implement robust security practices, including inventorying AI agents, safeguarding local credentials, and educating users on common malware delivery methods.

Cybercriminals are significantly expanding the scope of their information-stealing malware campaigns by specifically targeting data generated and stored locally by artificial intelligence (AI) coding agents. This development puts a wealth of sensitive information at risk on computers already compromised by infostealers.

Table Of Content

  • Key Takeaways
  • Hackers Target Claude, Cursor, and Codex AI Agents
  • Stolen Tokens Expose Work Context
  • What You Should Do

The targeted data includes critical elements such as access tokens, saved connection details, comprehensive prompt histories, and project records. It is crucial to note that this emerging threat does not stem from newly discovered vulnerabilities within AI platforms like Claude, Cursor, or Codex. Instead, it highlights how threat actors are adapting their existing infostealers to identify and exfiltrate valuable files predictably stored in local directories, a concern previously echoed in reports detailing Claude session theft via browser-based account access.

Analysts at Gen Digital said in a report that their research identified these expanded collection rules after scrutinizing recent malware activity. The findings specifically pertain to locally installed development agents, not direct compromises of the AI models or their underlying agents themselves.

The ramifications of such a theft can extend far beyond merely compromising a single paid account. A stolen archive can provide attackers with persistent access to an account and critical context, enabling them to identify sensitive projects, connected services, and individuals ripe for subsequent fraud or sophisticated phishing attacks.

Hackers Target Claude, Cursor, and Codex AI Agents

Over a three-month period, Gen Digital observed a notable increase in detections of infostealers such as Amatera and Remus across tens of thousands of protected Windows users. Amatera specifically focused on data associated with Cline and Continue, while Remus targeted Claude, Cursor, and OpenCode. This pattern strongly suggests that data from AI agents has become a valuable commodity within the broader infostealer ecosystem.

Further illustrating this trend, CallbackBeaver has also integrated Cursor and Claude into its data collection objectives, with over 5,000 samples identified within a 30-day window. The rapid proliferation of this technique is further evidenced by the involvement of other infostealers, including BeeStealer, STG Stealer, HydraStealer, APEX Stealer, and Otter Stealer. For macOS users, the Djinn Stealer has been linked to the compromise of data from Claude, Codex, Gemini, Cline, OpenCode, and Kilo agents.

A significant factor contributing to this rapid expansion is the ease with which criminals can update their malware. Many infostealers utilize remotely managed rules that define target folders, file names, databases, extensions, and search parameters. This means that adding a new target, such as an AI agent’s local data, often requires only a simple configuration update delivered to already compromised machines, rather than a complete rebuild of the malicious payload.

This low barrier to entry is critical because a local agent directory can harbor much more than just basic settings. Security teams investigating AI agent artifacts should consider authentication files, conversation databases, recent project data, and connected service settings as highly valuable endpoint material, akin to browser profiles and cloud command-line credentials.

Stolen Tokens Expose Work Context

Many AI agents store access tokens or refresh tokens locally to streamline the user experience by eliminating the need for repeated logins. A stolen access token can grant an attacker unauthorized access to an account until its expiration, while a refresh token can sometimes extend this window, facilitating persistent paid API abuse or the resale of active account access.

The presence of MCP (Managed Configuration Profile) configurations can escalate the risks even further. These files may contain critical information such as API endpoints, HTTP headers, environment variables, API keys, or other authentication details for external tools. Compromising these files could expose reusable secrets that provide access to source control systems, ticketing platforms, databases, cloud resources, or collaboration services connected to the AI agent.

Prompt histories and conversation transcripts are equally valuable to intruders. Developers frequently use AI assistants to review code, analyze logs, and troubleshoot incidents. Their chat logs can inadvertently reveal sensitive information, including proprietary source code, internal hostnames, repository names, deployment specifics, or even secrets that were temporarily pasted during a debugging process.

Related MCP security weaknesses underscore the necessity for meticulous oversight of connected tools. Organizations should maintain a comprehensive inventory of all AI agents in use, thoroughly review what data they store locally, and leverage operating-system-protected credential storage mechanisms wherever available. It is imperative to prevent passwords, private keys, API secrets, and customer data from being entered into AI prompts. Furthermore, connected tools should be granted only the minimum necessary permissions, and organizations should prioritize the use of short-lived, narrowly scoped tokens.

What You Should Do

  • Post-Infection Response: If a stealer infection is suspected, immediately revoke all AI agent sessions and rotate API keys and other connected credentials from a clean device. Review account activity for anomalies and determine if local conversations exposed sensitive company information.
  • Credential Management: Never paste passwords, private keys, API secrets, or sensitive customer data directly into AI prompts. Utilize operating-system-protected credential storage where available.
  • Token Best Practices: Employ short-lived, narrowly scoped tokens for AI agent access to external services.
  • Permission Review: Grant connected tools only the absolute minimum necessary permissions.
  • Endpoint Security: Keep all operating systems, applications, and security software updated to protect against known vulnerabilities.
  • User Education: Educate users about common malware delivery vectors, such as ClickFix or FakeCaptcha instructions, cracked software, and unofficial installers, and advise them to avoid these sources.
  • AI Agent Governance: For teams deploying coding agents at scale, establish robust approval processes. Review trusted projects, connections, and access boundaries before agents are widely adopted to prevent them from becoming an attacker’s shortcut.
  • Multi-Factor Authentication (MFA): While important, understand that MFA may not prevent the replay of a token already exfiltrated by malware.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

ClickFix Uses Google Sheets to Hijack Crypto Wallets

Next Post

Autonomous AI Agents Launch Mass Credential Theft Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Windows BitLocker Flaw Lets Attackers Remotely Execute Code
September 9, 2026
Critical cPanel CVE-2024-XXXX Vulnerability Lets Attackers Gain Full Server Control
September 9, 2026
CISA Warns Chinese AI Firms Stealing Billions of LLM Tokens
September 9, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us