Security researchers reported that AI coding agents are increasingly setting off endpoint detections because their routine actions resemble attacker tradecraft on both macOS and Windows systems. Hunt & Hackett described a macOS investigation in which a shell process ran
security dump-keychain -a
and filtered the results for a Bitbucket API token, initially appearing to be credential theft before investigators tied the activity to a legitimate developer using an AI-assisted coding environment. Sophos separately observed Windows telemetry showing agents such as Claude Code, Cursor, OpenAI Codex, and tools built on GStack triggering detections associated with Credential Access and Execution, including DPAPI-based browser credential decryption, Python access to browser credential stores, and cmdkey.exe enumeration of Windows Credential Manager entries.
The reported activity also included repeated LOLBin-based download attempts using trusted utilities and at least one blocked startup-folder persistence attempt linked to Cursor, underscoring how benign agent behavior can overlap with high-confidence intrusion signals. Researchers said the observed cases were not malicious, but warned that autonomous agents, weak logging of intent, prompt-injection risk, and permissive settings such as Claude Code's dangerous no-approval mode can turn similar workflows into genuine incidents. They recommended treating AI agents as a new execution layer with least privilege, isolation, stronger approvals for sensitive actions, and continued strict monitoring of credential-store access rather than broadly suppressing detections.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Over a seven-day period in June 2026, Sophos analyzed Windows telemetry and found AI coding agents such as Claude Code, Cursor, OpenAI Codex, and GStack-based tools repeatedly triggering behavioral detections. Observed activity included DPAPI-based browser credential decryption, Credential Manager enumeration, LOLBin download attempts, and a blocked startup-folder persistence attempt.
A security investigation examined endpoint detections triggered by a shell process running `security dump-keychain -a` and filtering for a Bitbucket API token on macOS. Investigators determined the activity was a benign true positive tied to a legitimate user's AI-assisted development workflow rather than credential theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcesophos.com
Open sourcehuntandhackett.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.