Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

Published September 9, 2026

Attackers are stealing data from AI coding tools like Claude, Cursor, and Codex when your computer is already infected with malware. They grab saved passwords, project files, and chat histories from these apps, then use them to target you with more scams.

Report priority
Medium

How it works

  • Attackers use existing malware like Amatera and Remus to scan your computer for files saved by AI coding tools.
  • These tools store your login tokens, project files, and conversation histories in predictable folders.
  • When malware finds these files, it steals them to reuse your account access and identify sensitive projects or people for follow-up fraud.

What to do

If you use Claude, Cursor, or Codex on Windows and your PC has been infected with malware like Amatera or Remus, check for recent malware infections by reviewing your antivirus logs or scanning with a trusted security tool. If you see these malware names, run a full malware scan on your Windows PC using a trusted antivirus like Windows Defender or Malwarebytes.

Remove any detected malware immediately. Update your AI coding tools to the latest version and check for any new security advisories. If you suspect your account was compromised, reset your passwords and review connected services for unusual activity.

Technical details

A malware infection on a developer's Windows PC scans for files saved by Claude, Cursor, and Codex. It extracts saved login tokens, project folders, and chat histories, then sends them to attackers. The attackers reuse the tokens to log into accounts and use the project details to craft targeted phishing emails.

Researchers at Gen Digital observed a growing trend where information-stealing malware, including Amatera, Remus, CallbackBeaver, BeeStealer, STG Stealer, HydraStealer, APEX Stealer, Otter Stealer, and Djinn Stealer, targets locally stored data from AI coding agents like Claude, Cursor, and Codex. Attackers exploit predictable local file paths to extract sensitive information, including API access tokens, saved prompt histories, project files, and connected service credentials from infected Windows and macOS systems. This activity does not stem from a new vulnerability in the AI agents themselves but reflects attackers adapting existing malware to harvest valuable data from common agent storage locations.

Over three months, Gen Digital detected tens of thousands of infections, with Remus and CallbackBeaver specifically targeting Claude and Cursor data, while Djinn Stealer expanded its scope to include macOS-based agents. Stolen archives may enable follow-on fraud, phishing, or account compromise beyond just the targeted accounts.