Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit AI Coding Agents for Data Theft

Hackers Exploit AI Coding Agents for Data Theft

Posted on September 9, 2026 By CWS

Cybercriminals are increasingly targeting AI coding agents such as Claude, Cursor, and Codex to extract sensitive data from infected systems. This emerging trend has raised concerns about the security of access tokens, saved connections, and prompt histories, which are stored locally on compromised computers. Although no new vulnerabilities have been discovered in these AI agents, attackers are adapting existing malware to locate valuable files within predictable directories.

Expanding the Reach of Malware

Recent analyses by Gen Digital revealed that cybercriminals are not directly compromising AI models themselves, but rather exploiting locally installed development agents. These findings highlight a significant threat, as a single stolen archive can grant criminals access to sensitive projects and connected services. This could lead to additional fraudulent activities, including phishing attacks.

During a three-month investigation, Gen Digital documented numerous instances of malware such as Amatera and Remus targeting Windows users. Amatera focused on data related to Cline and Continue, while Remus set its sights on Claude, Cursor, and OpenCode. This indicates that agent data has become a key target within the infostealer economy.

Widespread Impact on AI Development

Additional malware like CallbackBeaver has expanded its scope to include Cursor and Claude, with over 5,000 samples detected within a month. Other malware, including BeeStealer, STG Stealer, HydraStealer, APEX Stealer, and Otter Stealer, have rapidly adopted these techniques. Meanwhile, the macOS-targeted Djinn Stealer has been associated with a range of AI agents, underscoring the widespread impact of this threat.

The ease with which attackers can update their malware configurations to target new tools is a growing concern. These configurations often specify critical folders, file names, and databases, making it simple for criminals to add additional targets to already compromised machines.

Protecting Sensitive Information

Security teams are advised to pay close attention to files and databases associated with AI agents. These often include authentication files, conversation logs, and project data, all of which are high-value targets for cybercriminals. Additionally, stolen access tokens can provide unauthorized access to accounts, allowing for abuse of paid APIs and other sensitive resources.

Organizations should conduct thorough reviews of their AI agents and ensure that credentials are stored securely. They should also avoid embedding sensitive information in prompts and limit the permissions of connected tools. Multi-factor authentication remains crucial, although it may not prevent the misuse of already stolen tokens.

In the aftermath of a suspected malware infection, it is vital to revoke AI sessions, rotate API keys, and review account activities from a secure device. Keeping software updated and avoiding suspicious downloads can further reduce the risk of compromise. As AI coding agents become more prevalent in workplaces, the potential for exploitation will likely increase, necessitating continuous vigilance and proactive security measures.

Cyber Security News Tags:access tokens, AI development, AI security, Claude, Codex, Cursor, Cybercrime, Cybersecurity, data theft, Gen Digital, Infostealers, Malware, multi-factor authentication, Phishing, security teams

Post navigation

Previous Post: US Agencies Alert on China’s AI Data Extraction Strategy
Next Post: Critical Vulnerability in Alby Hub Exposes Bitcoin Wallets

Related Posts

FEMITBOT Network Abuses Telegram for Crypto Scams FEMITBOT Network Abuses Telegram for Crypto Scams Cyber Security News
Namastex npm Packages Compromised with CanisterWorm Malware Namastex npm Packages Compromised with CanisterWorm Malware Cyber Security News
AWS Enhances AI Agent Security with New Architecture AWS Enhances AI Agent Security with New Architecture Cyber Security News
YouTube Ghost Malware Network With 3,000+ Malicious Videos Attacking Users to Deploy Malware YouTube Ghost Malware Network With 3,000+ Malicious Videos Attacking Users to Deploy Malware Cyber Security News
How Threat Intelligence Will Change Cybersecurity in 2026 How Threat Intelligence Will Change Cybersecurity in 2026 Cyber Security News
Scaling SOC Team Expertise With AI-powered Insights for Faster, Easier Understanding of Threats Scaling SOC Team Expertise With AI-powered Insights for Faster, Easier Understanding of Threats Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus
  • Critical Vulnerability in Alby Hub Exposes Bitcoin Wallets
  • Hackers Exploit AI Coding Agents for Data Theft
  • US Agencies Alert on China’s AI Data Extraction Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus
  • Critical Vulnerability in Alby Hub Exposes Bitcoin Wallets
  • Hackers Exploit AI Coding Agents for Data Theft
  • US Agencies Alert on China’s AI Data Extraction Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark