Information-stealing malware operators are expanding collection rules to harvest locally stored artifacts from AI-assisted development tools including Claude, Codex, Cursor, Cline, Continue, OpenCode, Gemini, and Kilo. Targeted files can contain account and refresh tokens, API keys, MCP configuration secrets, connected-service credentials, prompt and conversation histories, project metadata, and account details—creating opportunities for account takeover, paid API abuse, intellectual-property exposure, phishing, and fraud. The activity does not exploit a vulnerability in the AI agents; stealers already installed on endpoints are being remotely reconfigured to collect predictable local data stores.
Gen Digital observed multiple established stealer families pursuing these artifacts, while BlackFog reported that the MaaS malware Bee Stealer v2.1 includes dedicated .codex and .claude collection paths and advertises theft of associated authentication data and chat histories. Bee Stealer also gathers browser and application data, system information, screenshots, and user files, then uses an "AI PC profile" feature to generate English- and Russian-language victim profiles from stolen logs. Its operator panel supports searching, filtering, tagging, bulk log downloads, and processing stolen Google access tokens, enabling criminals to quickly identify and prioritize high-value victims.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Okta analyzed a 7 GB infostealer dump released on Telegram on August 2, 2026, containing data from 5,871 infected machines in 162 countries. The dataset included thousands of unexpired AI-service authentication tokens and still-valid API keys that could be replayed or abused for account takeover and LLMjacking.
During the first half of 2026, Gen Digital telemetry recorded infostealer detections among more than 3.3 million unique protected users, with monthly detections exceeding 500,000 protected users.
Bee Stealer version 2.1 introduced an AI PC profile feature that generates English and Russian victim-profile files from stolen log data, apparently through external service-side processing. Static analysis also verified dedicated .codex and .claude collection paths, though the precise files or fields exfiltrated from those locations were not fully confirmed.
Amatera was observed targeting Cline and Continue data, while Remus targeted Claude, Cursor, and OpenCode; CallbackBeaver added Cursor and Claude artifacts to its collection scope. BeeStealer, STG Stealer, HydraStealer, APEX Stealer, Otter Stealer, and macOS-focused Djinn Stealer were also associated with AI-agent-data collection.
Multiple information-stealing malware families expanded remotely managed collection rules to target locally stored data from AI development agents, including Claude, Cline, Codex, Continue, Cursor, OpenCode, Gemini, and Kilo. The targeted artifacts can include session and refresh tokens, MCP configuration secrets, API keys, prompt histories, conversations, and project metadata; the activity does not rely on a vulnerability in the AI agents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceblackfog.com
Open sourcegendigital.com
Open sourceauth0.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.