Cybercriminals are increasingly targeting AI coding agents such as Claude, Cursor, and Codex to extract sensitive data from infected systems. This emerging trend has raised concerns about the security of access tokens, saved connections, and prompt histories, which are stored locally on compromised computers. Although no new vulnerabilities have been discovered in these AI agents, attackers are adapting existing malware to locate valuable files within predictable directories.
Expanding the Reach of Malware
Recent analyses by Gen Digital revealed that cybercriminals are not directly compromising AI models themselves, but rather exploiting locally installed development agents. These findings highlight a significant threat, as a single stolen archive can grant criminals access to sensitive projects and connected services. This could lead to additional fraudulent activities, including phishing attacks.
During a three-month investigation, Gen Digital documented numerous instances of malware such as Amatera and Remus targeting Windows users. Amatera focused on data related to Cline and Continue, while Remus set its sights on Claude, Cursor, and OpenCode. This indicates that agent data has become a key target within the infostealer economy.
Widespread Impact on AI Development
Additional malware like CallbackBeaver has expanded its scope to include Cursor and Claude, with over 5,000 samples detected within a month. Other malware, including BeeStealer, STG Stealer, HydraStealer, APEX Stealer, and Otter Stealer, have rapidly adopted these techniques. Meanwhile, the macOS-targeted Djinn Stealer has been associated with a range of AI agents, underscoring the widespread impact of this threat.
The ease with which attackers can update their malware configurations to target new tools is a growing concern. These configurations often specify critical folders, file names, and databases, making it simple for criminals to add additional targets to already compromised machines.
Protecting Sensitive Information
Security teams are advised to pay close attention to files and databases associated with AI agents. These often include authentication files, conversation logs, and project data, all of which are high-value targets for cybercriminals. Additionally, stolen access tokens can provide unauthorized access to accounts, allowing for abuse of paid APIs and other sensitive resources.
Organizations should conduct thorough reviews of their AI agents and ensure that credentials are stored securely. They should also avoid embedding sensitive information in prompts and limit the permissions of connected tools. Multi-factor authentication remains crucial, although it may not prevent the misuse of already stolen tokens.
In the aftermath of a suspected malware infection, it is vital to revoke AI sessions, rotate API keys, and review account activities from a secure device. Keeping software updated and avoiding suspicious downloads can further reduce the risk of compromise. As AI coding agents become more prevalent in workplaces, the potential for exploitation will likely increase, necessitating continuous vigilance and proactive security measures.
