Skip to content
Security & Trust

Warden infostealer reportedly targets Claude Code and AI coding tool keys

Version 1.9 reportedly targets Claude Code and Codex CLI files, so an agent's login is only as safe as the machine.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Warden infostealer reportedly targets Claude Code and AI coding tool keys
In brief
  • Hudson Rock's research site reports Warden Stealer v1.9 targets Claude Code and Codex CLI directories. Logs show stolen Anthropic/Claude API keys and OAuth data.
  • Stolen command-line tokens skip web logins, so an agent's access depends on the security of the developer's machine.
  • Ask where agent credentials are stored, how fast they can be revoked, and whether antivirus is the only defense.

An AI agent's login is a file on a computer

When a developer signs in to an AI coding tool, the tool saves a credential on the machine. That saved credential lets the tool work without asking for a password again. The lesson of the Warden report is plain. The agent's identity is only as safe as the machine it runs on.

Infostealers.com is the research site of security firm Hudson Rock. It reported on Warden on October 7. Warden is malware sold on dark web forums as an "all-in-one" stealer, clipper and loader. An infostealer is a program that copies the secrets stored on a computer.

What the researchers found

The report says version 1.9 goes after AI coding agents and developer setups. Payload folders that leaked online name the places Warden searches. They include the data folders of Claude Code and Codex CLI. They also include GitHub and SSH key locations.

The researchers also looked at logs pulled from infected machines. One stolen .claude.json file held a readable API key in its primaryApiKey field. It also held OAuth account details for an Anthropic/Claude account. OAuth is the sign-in system that lets an app act for a user. For Codex CLI, the report shows that its directory is targeted. It does not show stolen Codex data.

The report says this lets attackers skip web logins. They get direct access to paid AI models and company workspaces. Source code passing through these tools may also be exposed.

360+
Applications targeted by Warden's grabber
Source: infostealers.com / Hudson Rock (October 7, 2026)

How the theft works

Warden's data grabber reaches more than 360 applications in 13 categories. These include messengers, gaming clients, password managers, VPNs and FTP clients. It also copies Chromium and Gecko browser profiles. That means saved passwords, autofill data and full session cookies.

A session cookie is a token that proves someone already signed in. A command-line token does the same job for developer tools. With either one, the attacker never sees a login page. The report says stolen cookies can restore live, signed-in sessions.

The report lists several ways Warden avoids detection. It sends data over a custom encrypted protocol, not ordinary web requests. Network sensors cannot read that traffic.

It also rewrites its own code. The report says this makes signature-based antivirus, including Windows Defender and Avast, useless. Signature-based tools spot malware by matching known patterns.

Finally, Warden leaves decryption to the attacker's servers. That keeps the program small, at about 350kb.

Stolen logs are used against other secrets

Warden also targets cryptocurrency. It supports over 200 wallet extensions and desktop apps across 96 networks. When it steals an encrypted wallet, it does not use a standard password list. It builds a custom one from the victim's own log. The list draws on browser passwords, emails, search queries and autocomplete data.

Next, it runs that list through more than 490 rewrite rules. Each wallet can end up with as many as 20 million guesses.

The point for executives goes beyond crypto. One infection hands an attacker a person's whole set of password habits.

Up to 20 million
Maximum password guesses per wallet from the auto-bruteforce engine
Source: infostealers.com / Hudson Rock (October 7, 2026)

The developers say their new checker scanned over 61,700 addresses in a few days. They claim it cracked 66% of wallets that held a balance. They say the run brought in over $485,000. These are the sellers' own boasts. The report does not verify them.

66%
Wallets with a balance cracked, per Warden's developers' claim
Source: infostealers.com / Hudson Rock, citing the developers (October 7, 2026)

A business with tiers and support

The report says Warden runs like a software company. Subscriptions reach $1,500 a month for "Enterprise" users. Buyers get customer support and steady feature updates. Adding AI agent folders to the target list looks like one more product update.

$1,500
Top Warden subscription tier, per month
Source: infostealers.com / Hudson Rock (October 7, 2026)

What the report leaves open

Hudson Rock sells protection against infostealer infections, and the article ends with a sales pitch. The excerpt reviewed here does not say how many AI accounts were compromised. It does not explain how Warden reaches victims. It includes no response from AI providers.

The report also carries an interview with Warden's operators. That interview was not part of the material reviewed for this story.

This is one tool in one report. It does not show a wider trend. It does show that agent credentials are named targets in at least one commercial stealer.

Questions to put to your team

Where do our developers' AI tool credentials live? Who keeps a list of those accounts? Can we revoke an agent's key quickly if a developer machine is compromised? Do we check what code and workspaces an agent token can reach?

Ask also whether endpoint defenses rely only on signature-based antivirus. The report says Warden is built to beat that approach. Then ask whether employee devices are checked against stolen-log intelligence. A login stolen from an infected machine can look like a normal session.

An AI agent works with a badge, and that badge is a file. Protect it like one.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: infostealers.com.

Share this insight