Ethics and safety·October 9, 2026, 10:10

Warden Stealer: New malware steals data from Claude, Codex, Grok and Cursor

AI-generated and checked against the sources listed below.

The malware Warden Stealer now also steals access keys and conversation history from AI tools such as Claude, Codex, Grok and Cursor. That's according to the security company Gen Digital.

AI-generated image

A piece of malware called Warden Stealer is now going after data from AI assistants and AI coding tools. That's according to an analysis from the security company Gen Digital.

Warden Stealer is a so-called infostealer. It is a program that sneaks onto a computer and steals information such as passwords, cookies (small files that remember you are logged in) and cryptocurrency. The program is written in the Rust language and is sold as a subscription service to other criminals.

What gets stolen

According to Gen Digital, the program targets configuration files and local data from AI tools such as Claude, Codex, Grok and Cursor. This includes:

- access and refresh keys (tokens) that keep a user logged in - login credentials stored in MCP setups, which connect AI tools to other services - history of what users have asked the AI - conversation databases - traces of the projects developers are working on

That is valuable to criminals. According to Gen Digital, data from AI tools provides both access to an account and an overview of what lies behind it. Old prompts can, for example, reveal which systems and projects a company is working on.

From special feature to standard

The feature was initially not part of what was advertised. Some criminals used it through their own rules for what the program should collect. With version 1.9, announced on September 29, 2026, the developers built in the collection of AI keys as standard.

The program began being marketed in August 2026 and, according to Gen Digital, has quickly become one of the most widespread infostealers. Early versions could be traced back to May 2026.

In addition to AI tools, it targets all the major browsers, more than 200 crypto plugins and more than 360 other targets such as messaging services, password managers and VPN clients. According to other security media, it spreads through fake installation guides, malicious ads, pirated software and game cheats, among other things.

What it means for you

The attack does not hit the AI services themselves, but computers that are already infected. The risk is greatest for developers and companies that have AI tools connected to code and internal systems. Gen Digital does not give specific advice to ordinary users in the analysis.

The usual caution applies, though: avoid pirated software and game cheats, and be careful about copying commands from websites into your computer.

Sources

More on this topic

Get the week's AI news in your inbox

Choose your level, topics and length. One email a week, unsubscribe at any time.

Subscribe to Promptly Newsletter
PromptlyNewsletterRSSLog in

The news on aijour is AI-generated and checked against the cited sources.