Agents store long-lived credentials so they can work without repeated logins. Those credentials, and the MCP configuration files that hold API keys for connected systems, have become a target for commodity malware.
Commonly stolen agent data includes:
In 2026, researchers documented at least ten infostealer families targeting coding agents such as Claude, Cursor, and Codex, with detections across tens of thousands of users.
Defenses include short-lived, scoped credentials for agents, centralized secret handling through gateways, endpoint discovery of exposed configs, and revoking agent sessions after any infection.
How PointGuard AI Helps
PointGuard AI Agent Identity & Access Security issues scoped, short-lived authorization for agents, the MCP Security Gateway keeps secrets out of local config files, and Agentic Endpoint Security finds exposed agent credentials on devices.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.