SpecterOps released Blacklight, an open-source toolkit that identifies and analyzes local artifacts left by AI coding agents including Codex, Claude Code, Cursor, and Antigravity CLI. The research warns that if an attacker gains access to a workstation, these files may reveal authentication tokens, session histories, project metadata, environment variables, and connected-service details. Blacklight supports Windows, macOS, and Linux, prioritizes high-value artifacts for review, and can integrate with tools such as Nemesis and TruffleHog to expand secret discovery and offline analysis.
The release follows renewed attention on how AI assistants store local transcripts after a widely discussed sysadmin post reported that Claude Code kept plaintext JSONL session logs under user profile directories, including prompts, responses, tool calls, and tool results. The post described 787 files totaling 1.1GB on one machine and warned that pasted secrets such as .env contents, connection strings, authentication headers, and tokens in logs could persist on endpoints and in backups. SpecterOps urged organizations to inventory AI agent use, restrict access to profile directories, monitor credential-file access, review trusted-project settings, and define retention policies for AI session data.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
SpecterOps released Blacklight, an open-source toolkit for identifying and analyzing local artifacts created by AI coding agents including Codex, Claude Code, Cursor, and Antigravity CLI. The research emphasized that these artifacts can expose tokens, session history, environment variables, project details, and connected-service information to attackers with workstation access.
A post on r/sysadmin claimed Claude Code stores local session transcripts as plaintext JSONL files under user profile directories, including prompts, responses, tool calls, and tool results. The post warned that secrets pasted into prompts or exposed in logs could persist on endpoints and in backups if retention and protection controls are not in place.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.