Identity & Access · Credential Theft

Infostealers Now Reach Developer AI Sessions

Wiz Research published new findings showing infostealers are now harvesting AI-assistant credentials alongside cloud keys, browser cookies, and code-platform sessions from developer endpoints. The same haul can include active tokens for tools such as Anthropic Claude, so one infected laptop can expose more than just a local account.

The malware does not have to crack passwords or MFA. It scrapes whatever the endpoint already has cached or open — API keys, cookies, and session tokens — and then reuses those live credentials from elsewhere, which turns a desktop infection into access to cloud consoles, source control, and AI services.

If developers use cloud, code, and AI tools on the same machine, the durable exposure sits in the reusable sessions the endpoint handed over, not only in the malware itself. Revoking the local infection does not by itself answer what the stolen tokens can still unlock.

1 source · 2 days ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-28

Every edition of this story: Infostealers Now Reach Developer AI Sessions

More from today