Infostealers Raid AI Coding Agents for Tokens and MCP Configs

Key Takeaways

  • At least ten infostealer families now target local data stored by AI coding agents.
  • Targets include Claude, Cursor, Codex, Gemini, Cline, OpenCode, and others.
  • Stolen data includes access and refresh tokens, MCP configurations, prompt histories, and project data.
  • Token replay can bypass multi-factor authentication until tokens expire or are revoked.
  • Detections reached tens of thousands of protected users over three months.

Commodity Malware Learns to Speak AI Agent

Research from Gen Digital shows commodity infostealer malware has added AI coding agents to its target lists, harvesting tokens and configuration files from developer machines. As Cybersecurity News reported, the activity spans multiple malware families and is being observed at scale.

What We Know

Gen Digital identified infostealer families targeting AI tools on Windows and macOS. Amatera targets Cline and Continue; Remus targets Claude, Cursor, and OpenCode; CallbackBeaver, which produced more than 5,000 samples in 30 days, targets Cursor and Claude; and the macOS stealer Djinn targets Claude, Codex, Gemini, Cline, OpenCode, and Kilo. Others include BeeStealer, STG Stealer, HydraStealer, APEX Stealer, and Otter Stealer.

The malware collects access and refresh tokens, MCP configuration files, prompt histories, conversation databases, saved connections, and project metadata from predictable file locations. Gen recorded Amatera and Remus detections among tens of thousands of protected users over three months.

What Happened

This is credential theft adapted to the AI era. AI agents store long-lived tokens and connection details on disk so they can work without repeated logins. MCP configuration files often hold API keys, endpoints, and environment variables for connected systems such as code repositories, databases, and SaaS tools.

An attacker who copies these files can replay sessions without passing multi-factor authentication, and a refresh token can extend that access. Prompt histories add another layer of exposure, since developers often paste code, secrets, and internal details into agent conversations. The infection itself uses ordinary methods such as cracked software and fake installers.

Why It Matters

AI coding agents concentrate access. One stolen agent profile can reveal source code, cloud credentials, and every system connected through MCP. Because the stolen tokens are valid, activity may look legitimate to identity providers.

This turns the developer endpoint into a gateway to the AI toolchain. Organizations that rotate passwords after an infection but do not revoke AI agent sessions and MCP secrets may leave attackers with working access.

PointGuard AI Perspective

AI agents need to be treated as identities with credentials worth protecting. PointGuard AI Agentic Endpoint Security discovers AI coding agents, MCP servers, and their configurations on managed devices, highlighting exposed secrets and risky setups before malware finds them.

PointGuard AI Agent Identity & Access Security gives agents distinct, verifiable identities with scoped, short-lived authorization instead of reusable long-lived tokens, and the MCP Security Gateway centralizes tool access so secrets do not sit in local config files. Trustworthy adoption of coding agents depends on making stolen agent credentials far less useful.

Incident Scorecard Details

Total AISSI Score: 6.6/10

Criticality: 7, Agent tokens and MCP configs can unlock source code, cloud resources, and connected enterprise systems. AISSI weighting: 25%

Propagation: 6, One stolen profile can expose every service connected through the agent's MCP configuration. AISSI weighting: 20%

Exploitability: 8, Multiple malware families are actively stealing this data in the wild. AISSI weighting: 15%

Supply Chain: 6, The risk spans many third-party AI coding tools and their local credential storage. AISSI weighting: 15%

Business Impact: 6, Infections are widespread, though specific downstream breaches have not been publicly attributed. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

7

Propagation

6

Exploitability

8

Supply Chain

6

Business Impact

6

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.