Infostealer Logs Expose Replayable AI Session Tokens and API Keys
Cybercriminals are harvesting authentication credentials from compromised systems to hijack accounts for Claude, ChatGPT, Gemini, and other LLM services.

Stolen credentials grant backdoor access to AI platforms
Cybercriminals are exploiting information stealer malware to harvest authentication tokens and API keys that provide unauthorized access to artificial intelligence services from Google, Anthropic, OpenAI, and other major providers. Once stolen, these credentials enable attackers to bypass traditional login protections—including multi-factor authentication—by replaying valid session tokens.
Okta analyzed a 7 GB infostealer dump released on Telegram in August 2026 containing data from 5,871 infected machines across 162 countries. The dataset included 44,791 unique JSON web tokens, with 555 likely tied to AI service authentication. On the day of release, 1,843 of these tokens remained unexpired and exploitable, according to findings first reported by The Hacker News.
Jeremy Kirk, director of threat intelligence at Okta, explained that session tokens and API keys allow threat actors to effectively log into LLM services without credentials. "Use of these skeleton keys makes abuse more challenging but not impossible to detect," he noted.
Why it matters
As enterprises rapidly adopt AI tools, the attack surface has expanded beyond traditional credentials. Stolen session tokens bypass even strong authentication measures like passkeys, while compromised API keys enable resource theft that can generate massive compute bills for victims. The emergence of underground markets selling discounted access to premium AI models signals a maturing threat economy around LLM services.
Underground markets sell stolen AI access
The stealer dump also contained 24 valid API keys for services including Google Gemini, OpenAI, Groq, and OpenRouter. Attackers can weaponize these keys for espionage, extortion, or to rack up AI token bills on victim accounts—a practice known as LLMjacking, analogous to cryptomining attacks.
New black market sites have emerged selling bundled access to Claude, Cursor, ChatGPT, and Gemini at discounted rates. One vendor advertised 24/7 support and money-back guarantees. Another service, Poison Claude, claims to provide access to multiple versions of Anthropic's Opus and Sonnet models.
These operations rely on specialized tooling. Anti-detect browsers allow attackers to use stolen authentication data while evading security controls. Open-source tools like Camoufox and SeleniumBase can load stolen browser session data from files and configure proxies to bypass impossible-travel detection.
Tokens expose personal data and compute resources
Nearly 18% of the analyzed JWTs contained plaintext personally identifiable information, including names, phone numbers, and email addresses. This data persists indefinitely and can fuel social engineering or phishing campaigns.
Google's Mandiant team documented one incident where an attacker used an exposed GitHub Personal Access Token to deploy unauthorized AI infrastructure and scale high-performance compute resources in a victim's cloud environment. Google Threat Intelligence Group observed increased targeting and sale of AI accounts across cybercrime communities, driven by the high cost of premium model access and compute power.
Defense requires token monitoring and scoped access
While IP allowlisting and Google's Device Bound Session Credentials can mitigate some session replay attacks, organizations need broader protections. Okta recommends monitoring for session token reuse, scoping API keys narrowly, and implementing OAuth 2.0 flows with short-lived tokens that expire quickly if stolen.
"As frontier model access grows more expensive, the incentive to steal rather than pay for it grows too," Kirk said. "Stronger authentication and phishing-resistant technologies such as passkeys has made username-and-password takeovers harder, but it does not stop a stolen session token or API key."
The findings were detailed in a report from Okta shared with The Hacker News.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
