Infostealers Raid AI Coding Agents for Tokens and MCP Configs
Key Takeaways
- At least ten infostealer families now target local data stored by AI coding agents.
- Targets include Claude, Cursor, Codex, Gemini, Cline, OpenCode, and others.
- Stolen data includes access and refresh tokens, MCP configurations, prompt histories, and project data.
- Token replay can bypass multi-factor authentication until tokens expire or are revoked.
- Detections reached tens of thousands of protected users over three months.
Commodity Malware Learns to Speak AI Agent
Research from Gen Digital shows commodity infostealer malware has added AI coding agents to its target lists, harvesting tokens and configuration files from developer machines. As Cybersecurity News reported, the activity spans multiple malware families and is being observed at scale.
What We Know
Gen Digital identified infostealer families targeting AI tools on Windows and macOS. Amatera targets Cline and Continue; Remus targets Claude, Cursor, and OpenCode; CallbackBeaver, which produced more than 5,000 samples in 30 days, targets Cursor and Claude; and the macOS stealer Djinn targets Claude, Codex, Gemini, Cline, OpenCode, and Kilo. Others include BeeStealer, STG Stealer, HydraStealer, APEX Stealer, and Otter Stealer.
The malware collects access and refresh tokens, MCP configuration files, prompt histories, conversation databases, saved connections, and project metadata from predictable file locations. Gen recorded Amatera and Remus detections among tens of thousands of protected users over three months.
What Happened
This is credential theft adapted to the AI era. AI agents store long-lived tokens and connection details on disk so they can work without repeated logins. MCP configuration files often hold API keys, endpoints, and environment variables for connected systems such as code repositories, databases, and SaaS tools.
An attacker who copies these files can replay sessions without passing multi-factor authentication, and a refresh token can extend that access. Prompt histories add another layer of exposure, since developers often paste code, secrets, and internal details into agent conversations. The infection itself uses ordinary methods such as cracked software and fake installers.
Why It Matters
AI coding agents concentrate access. One stolen agent profile can reveal source code, cloud credentials, and every system connected through MCP. Because the stolen tokens are valid, activity may look legitimate to identity providers.
This turns the developer endpoint into a gateway to the AI toolchain. Organizations that rotate passwords after an infection but do not revoke AI agent sessions and MCP secrets may leave attackers with working access.
PointGuard AI Perspective
AI agents need to be treated as identities with credentials worth protecting. PointGuard AI Agentic Endpoint Security discovers AI coding agents, MCP servers, and their configurations on managed devices, highlighting exposed secrets and risky setups before malware finds them.
PointGuard AI Agent Identity & Access Security gives agents distinct, verifiable identities with scoped, short-lived authorization instead of reusable long-lived tokens, and the MCP Security Gateway centralizes tool access so secrets do not sit in local config files. Trustworthy adoption of coding agents depends on making stolen agent credentials far less useful.
Incident Scorecard Details
Total AISSI Score: 6.6/10
Criticality: 7, Agent tokens and MCP configs can unlock source code, cloud resources, and connected enterprise systems. AISSI weighting: 25%
Propagation: 6, One stolen profile can expose every service connected through the agent's MCP configuration. AISSI weighting: 20%
Exploitability: 8, Multiple malware families are actively stealing this data in the wild. AISSI weighting: 15%
Supply Chain: 6, The risk spans many third-party AI coding tools and their local credential storage. AISSI weighting: 15%
Business Impact: 6, Infections are widespread, though specific downstream breaches have not been publicly attributed. AISSI weighting: 25%
Sources
Third-Party Sources
- Gen Digital: Infostealers are coming for your AI agent
- Cybersecurity News: Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens
