Identity · 2 days ago
Wiz Research published new findings showing infostealers are now harvesting AI-assistant credentials alongside cloud keys, browser cookies, and code-platform sessions from developer endpoints. The same haul can include active tokens for tools such as Anthropic Claude, so one infected laptop can expose more than just a local account.
The malware does not have to crack passwords or MFA. It scrapes whatever the endpoint already has cached or open — API keys, cookies, and session tokens — and then reuses those live credentials from elsewhere, which turns a desktop infection into access to cloud consoles, source control, and AI services.
If developers use cloud, code, and AI tools on the same machine, the durable exposure sits in the reusable sessions the endpoint handed over, not only in the malware itself. Revoking the local infection does not by itself answer what the stolen tokens can still unlock.
1 source covering this story
The Infostealer Incursion: Cloud, Code & AI Breaches | Wiz Blog
Wiz Research analyzes NordStellar data to map credentials targeted by infostealers and assess their impact across cloud, code, and AI environments.
Part of the PlainSec briefing for 2026-09-28