Warden Infostealer Hunts AI Agent Keys, Exfiltrates Claude CLI Tokens

Malwarebeasts · reddit · 2026-10-07

Analysis of the Warden infostealer shows it actively targeting AI agents and developer credentials. Log extractions reveal a compromised .claude. leaking raw primaryApiKey values and detailed OAuth data tied to Anthropic/Claude accounts. By grabbing CLI tokens, attackers bypass web logins entirely, gaining programmatic access to premium AI models, organizational workspaces, and sensitive source code.

Original post →

More from Safety

Safety channel →