Attackers are stealing AI platform API keys and using them to consume paid model services on victims’ accounts, a practice Unit 42 describes as AI token jacking. The activity has generated nearly $1 million in fraudulent charges before some victims detected the abuse, with malicious infrastructure in some cases driving tens of millions of API calls per day. Stolen credentials are being monetized directly and also funneled through gray-market "transfer stations" that resell access to legitimate AI services using compromised or discounted accounts.
The stolen keys are being obtained through phishing, infostealer malware, exposed file shares, public code repositories, and poisoned software packages, including self-propagating npm packages that can steal credentials and taint later releases. Defenders are being urged to revoke exposed keys immediately, monitor billing and usage for anomalies, enforce spending caps and short-lived tokens, tighten privileged-account controls, restrict network access, and strengthen software supply-chain hygiene; reporting also points to indicators of compromise such as suspicious user-agent strings, malicious IP addresses, and domains linked to transfer-station infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The reporting included indicators of compromise associated with malicious API calls and transfer-station infrastructure, including the user-agent string "Go-http-client/2.0,gzip(gfe)," domains such as amutes[.]com and abb1[.]life, and multiple IP addresses tied to credential theft or abuse.
The report highlighted poisoned, self-spreading npm packages as an especially concerning way attackers steal developer, cloud, and AI credentials. It said a malicious package can exfiltrate credentials from a developer environment and contaminate later software releases.
Unit 42 linked the activity to gray-market intermediary services called transfer stations that resell access to official AI platforms using stolen or discounted credentials. In incidents reviewed by the researchers, this infrastructure generated tens of millions of API calls per day and drove victim fees into the hundreds of thousands of dollars.
Unit 42 reported a growing pattern of "AI token jacking," in which attackers steal or expose AI API credentials and abuse victims' paid model access. The report said Palo Alto Networks had observed nearly $1 million in charges accrued before victims detected and contained the abuse.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecybersecuritynews.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.