The cheapest way to compromise your agent in 2026 is to not touch your agent at all. Gen Threat Labs' 8 September 2026 research documents commodity infostealers extending their collection rules to the local artifacts of AI coding tools — Claude, Cursor, Cline, Continue, Codex, OpenCode — and what those rules harvest is not just a token. It is a token plus a machine-readable list of every system that token's owner wired an agent into, plus a searchable history of what they asked it to do. No prompt injection, no jailbreak, no model involvement: adding your tooling to that pipeline is a remote configuration update to machines that are already compromised.
At a glance
Three figures carry the argument, and none of them is about model behaviour.
| Figure | Value | What it tells you |
|---|---|---|
| Commodity stealer families collecting AI-tool artifacts | Eight, as of 8 Sep 2026 | Not a targeted campaign. A line item in mass-market malware. |
| CallbackBeaver samples in one 30-day window | 5,000+ | The family that added Cursor and Claude is also one of the fastest-growing. |
| Gen infostealer detections, H1 2026 | 3.3M unique protected users | Monthly totals above 500,000. This is the delivery channel that already exists. |
| Claude Code refresh-token validity | 27 days | From a 1 Sep 2026 report against the project. The access token's one-hour TTL is beside it. |
| File mode on the Linux credentials file | 0600 | A boundary against other users. The stealer is running as you. |
| Artifact classes harvested | Five | Credentials, connection config, transcript history, project metadata, harness config. |
The research names which family went after what: Amatera collecting Cline and Continue data, Remus collecting Claude, Cursor and OpenCode, CallbackBeaver adding Cursor and Claude to its scope, with BeeStealer, STG Stealer, HydraStealer, APEX Stealer and the macOS-focused Djinn Stealer also associated with AI-agent collection. The rules themselves are remotely managed — folders, filenames, databases, extensions, search limits — which is the detail that sets the economics.
Nobody had to attack the agent
Almost every control in agent security assumes the agent is the thing being attacked. Prompt-injection defence, tool-poisoning review, sandbox escape hardening, approval gating, scope conformance — all of it is about what happens inside a running loop when an adversary gets text or code into it. That work is necessary and this is not it. Here the loop never runs. A process already on the machine reads four or five files and leaves.
What makes this a different problem rather than a smaller one is the shape of what is on disk. In a server-side system, a credential, the inventory of systems that credential reaches, and the historical record of its use live in three separate trust zones with three different review processes. An agent install collapses all three into one directory, under one user account, on a laptop that is not in anyone's production inventory. The collapse is not a bug in any particular tool — it is what "works out of the box" means.
The delivery economics are the part to internalise. Because the collection rules are config, not code, the lag between a new agent gets popular and a stealer collects its artifacts is however long it takes an operator to push a rule. Gen recorded infostealer detections against 3.3 million unique protected users in the first half of 2026, with monthly totals above 500,000. The distribution network is built, paid for and running. Your tooling is a row in its configuration.
The pair sets the lifetime, not the token
Read the credential storage of a shipping product and the arithmetic is right there. Claude Code keeps its login in the OS keychain where it can, and falls back to ~/.claude/.credentials.json at mode 0600 — the Linux default, and the Windows and locked-keychain path too. A report opened against the project on 1 September 2026 records that file holding a live access token alongside a refresh token valid for twenty-seven days, with the observed expiries a month apart. Nothing about that is careless by the standards of the field. It is the normal shape, which is why it generalises.
The consequence is that the short access-token TTL is not doing the security work people think it is. A refresh token renews without re-authentication; if no human, device check or attestation participates in the refresh, nothing in the loop can notice that the renewer changed. The lifetime of the pair is the refresh token's, and the one-hour access token has quietly become a latency property rather than a security property. The question for a design review is not "what is our TTL" — it is "if this directory is copied, how long does the copy keep working".
Mode 0600 deserves the same deflation. It is a correct and useful control against a different user on the same host. Credential-stealing malware is running as that user, so the permission bits are satisfied rather than bypassed: nothing is broken, nothing alerts, and the file is read exactly as the owner would read it. The same holds for the keychain when the keychain is unlocked, which on a working developer machine is most of the time.
The second half of the loot is the tool list
Price these artifacts by what a holder can do with them alone and the ranking inverts the usual instinct. The credentials file is the one everybody thinks about, and it is also the only one with a clock and a kill switch. The MCP server config has neither, and it is worth more than any single secret inside it: it is an enumerated, curated, current list of the systems your organisation thought worth connecting an agent to, with the endpoints and header names to reach them. That turns a generic theft into a targeted one, and it answers the question that normally costs an intruder weeks of noisy scanning — not what exists but what matters.
Transcript history is the artifact teams underrate hardest. A week of a senior engineer's agent history is, in content terms, close to read access on the repositories plus the incident channel: pasted secrets, source code, customer names, and the reasoning about your architecture that an attacker would otherwise have to reconstruct. Unlike a token it cannot be revoked. The only control that applies to it is retention, which means the retention window you set for convenience is also an incident-response decision.
Project metadata rounds it out at almost no cost to the attacker: repositories, hosts, branches, tickets. No parsing, no secrets, just a precise answer to which organisation this is and what it runs. Taken together the four artifacts are a credential, a map of what the credential reaches, a history of what it was used for, and an identification of whose it is. That is not a leaked secret. It is an onboarding package.
Why your existing detection does not see it
The replay happens outside everything you instrumented. A harvested provider token used from somewhere else hits the provider's API directly, so your gateway, your egress allowlist and your trace store never observe it — those cover traffic leaving your network, and this traffic never enters it. The endpoint agent on the laptop may catch the stealer, which is worth having, but by the time you are investigating, the credential is in use from an address you have no relationship with.
That pushes detection to two places, and both of them are unglamorous. The first is provider-side telemetry: use from a new region or client fingerprint, use while the owning laptop is asleep, two concurrent sessions on one credential. Most teams have never asked their model provider what of this is available to them, and the answer is usually more than they expect. The second is a planted signal. An MCP server definition that no legitimate workflow ever calls, pointing at an endpoint you own, is the one unambiguous detector available on this surface — nothing but a reader of that file would ever touch it, which is exactly the property behavioural detection cannot give you when the subject is an agent that reads everything it can reach.
The structural fix is narrower than it sounds, and it is the same one in both halves of the problem: stop letting one artifact carry both the name and the route. A config that references a secret rather than containing it is one artifact instead of two. It still names your systems — that part is unavoidable if the agent is going to use them — but it no longer authenticates to them, and the index stops being a key.
What to do about it this month
In rough order of return, and none of these needs a budget cycle.
- Strip inline secrets out of MCP configs. Reference by name, resolve at launch from the OS keychain or a short-lived broker. A day of work, and it removes the highest-leverage artifact in the set.
- Write down the lifetime of the pair. For your highest-privilege agent credential, record the refresh token's validity, not the access token's. If the number is in weeks, that is your exposure window after a single laptop compromise.
- Time one revocation with a stopwatch. Revoke a real agent credential and record when the next call using it failed. Two things usually surface: nobody knew who could perform the revocation, and the drill finds a copy nobody listed.
- Plant one honeytoken MCP entry per install. The cheapest unambiguous signal you will ever deploy on a developer endpoint.
- Cap local transcript retention. Pick a window. Defaults keep everything forever because that is what users want, and history is the one artifact revocation cannot reach.
- Split the privileged install from the exploratory one. The agent that can reach production should not be the install that opens arbitrary repositories and runs arbitrary MCP servers.
What this is not is a reason to stop running agents locally, and it is not a case for a new product category. It is the observation that the developer endpoint became a production surface at some point in the last two years, that nobody updated the inventory, and that the people who maintain mass-market credential-theft pipelines noticed before the people who maintain agent security programmes did.
FAQ
Is this a vulnerability in Claude Code, Cursor or Codex?
No. Every tool named here stores credentials the way desktop software normally does, and uses the OS keychain where it is available. The finding is about what the aggregate of those files is worth once a machine is compromised by unrelated malware, and about the fact that commodity stealers now collect them by default.
Does the OS keychain solve it?
It raises the cost meaningfully and does not close the problem. A keychain that is unlocked — which is the normal state on a machine someone is working on — can be read by processes running as that user, and tools fall back to a plaintext file when the keychain write is rejected. It is the right default, not a boundary.
How is this different from prompt injection or tool poisoning?
Those are attacks on a running agent through its inputs: the model is induced to do something. Here the model is not involved at all. The agent's stored state is read while it is not running, which is why none of the defences aimed at the loop apply.
What single change helps most?
Removing inline secrets from MCP configurations, so the file that enumerates your internal systems no longer also authenticates to them. It is a day of work and it separates the two things an attacker most wants to find together.
Should we stop keeping agent conversation history locally?
Cap it rather than kill it — history is genuinely useful and you will lose the argument otherwise. Set a retention window, enable write-time redaction where the tool offers it, and decide in advance what a compromised transcript triggers, because unlike a token it cannot be revoked.
Further reading
On this wiki:
- Credential lifetime — why the pair's validity, not the token's TTL, is your exposure window.
- Agent artifacts on the endpoint — the five artifact classes, the inventory, and the revocation drill.
- Configuration as reconnaissance — what the tool list is worth on its own, and the six copies of it you keep.
- Secrets management for agents — the practices that stop at the server, and why they should not.
- Honeytokens for agent systems — placement rules for the one unambiguous signal on this surface.
- Detecting agent compromise — why behavioural baselines fail when the subject is anomalous by design.
Sources:
- Gen Threat Labs — infostealers and your AI agent (8 September 2026)
- anthropics/claude-code issue #91158 — credential file contents and token validity
- Claude Code authentication documentation — credential storage locations per platform