Security & AI news

Information stealers and AI agents · By FireAI Security & Research Team · Published

Gen Digital finds information stealers collecting tokens and prompt histories from AI coding agents, including on macOS

Gen Digital reports that Amatera, Remus and other information stealers now take access tokens, MCP settings and chat histories from Claude, Cursor and other agents.

A document with an alert bell and the FireAI firefighter mascot, next to the words “Stealers now take AI agent tokens and chats.”

Gen Digital reported on 8 September that commodity information stealers now collect the local data of AI coding agents: access and refresh tokens, MCP settings, prompt histories and conversation databases [1]. The company names one family that targets macOS, Djinn Stealer.

Background

Information stealers are programs that copy saved data from a computer and send it to their operator. Their usual haul is browser passwords, cookies and cryptocurrency wallets. AI coding agents keep their own files on disk, and Gen says the valuable parts are in predictable places and sometimes stored in plaintext [1].

What the report describes

Gen lists which families go after which tools. Amatera targets Cline and Continue. Remus targets Claude, Cursor and OpenCode. CallbackBeaver targets Cursor and Claude, and Djinn Stealer on macOS targets Claude, Codex, Gemini, Cline, OpenCode and Kilo. Lower-prevalence families named are BeeStealer, STG Stealer, HydraStealer, APEX Stealer and Otter Stealer [1].

Gen gives these figures from its own telemetry: 3.3 million unique protected users with an information-stealer infection in the first half of 2026, more than 500,000 monthly detections across all stealer families, over 5,000 CallbackBeaver samples in 30 days, and tens of thousands of users with Amatera or Remus detections over three months [1].

The research says stolen credentials paired with conversation histories show an attacker the context of an account, including proprietary code, internal infrastructure and trade secrets, which goes beyond a password reset [1].

Implications for Mac users

The report describes stealers already on a computer, not a flaw in an AI tool. Mac users who run coding agents and have never had a stealer installed are not affected by it. Those who do run agents should treat the agent's data folders as sensitive as a browser profile [1].

Recommendations

  1. Inventory what each local agent stores, and shorten how long chat history is kept where the tool allows it.
  2. Prefer the operating system’s credential store over token files, where the tool supports it.
  3. Keep secrets out of prompts.
  4. Limit MCP permissions and use short-lived tokens.
  5. After any suspected infection, revoke tokens and rotate credentials, not only passwords.

Relevance to FireAI

FireAI does not scan for stealers, hide agent files or remove an infection. It is relevant at the moment of exfiltration: an app with no rule that tries to connect triggers a prompt in Alert mode, Paranoid mode blocks unsigned apps, and Clipboard Armor flags a first connection made seconds after the clipboard changes. A stealer that reuses a connection an approved app is already allowed to make would not be asked about.

Limitations

The figures are Gen's own telemetry, may overlap between families and measure detections, not confirmed thefts. The report as fetched does not describe how the stealers reach the computer, and it gives no separate count for macOS. Readers should also keep in mind that the publisher sells security software, which is a reason to read its telemetry figures as company-reported rather than independently audited [1].

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. Gen Digital, 8 September 2026: Infostealers and your AI agent