Yaamlabs

Threat intel

Warden Stealer goes after Claude, Codex and Cursor tokens

A Rust infostealer sold as a service now lists AI coding agent tokens, MCP configs and prompt histories as targets. How it works and how to hunt for it.

Warden Stealer is an infostealer for Windows 8 to 11, written in Rust and rented out as malware-as-a-service, with its own loader and a cryptocurrency clipper (malware that swaps a copied wallet address for the attacker's) in the same build. Gen Threat Labs published a full analysis on October 8 and ranks it among the most common stealers its customers run into, next to Vidar, Amatera and Remus. Version 1.9, announced on September 29, added collection of data stored by AI assistants and coding agents: Claude, Codex, Grok and Cursor.

If your developers run Claude Code, Codex CLI or Cursor on Windows, the files those tools keep in the user profile are now on a commercial stealer's checklist. Those files hold tokens that work without a password or multi-factor authentication (MFA), plus the credentials agents use to reach other systems. Earlier coverage of stolen AI accounts was mostly about browser session cookies for ChatGPT and Claude on the web; Warden reads the agents' own local files, and Gen has published hashes and domains you can hunt for today.

How it works

Warden is sold to customers who run their own campaigns, so delivery varies. Gen has seen it arrive through cracked software, game cheats, malicious ads and ClickFix pages, where a fake verification prompt tells the user to paste a command into the Windows Run box or PowerShell. Most samples come wrapped in the built-in loader.

The loader finds the window called Shell_TrayWnd, which belongs to whatever process draws the taskbar, normally explorer.exe. It allocates executable memory in that process, writes the stealer DLL into it, maps it by hand and starts it with CreateRemoteThread. Older builds injected into msiexec.exe or dllhost.exe instead. Loader files are padded with a large block of junk data at the end, so scanners that skip big files never look at them.

Before stealing anything, Warden looks for signs of a virtual machine (missing SMBIOS cache records, hypervisor names from the CPUID instruction, Virtio drivers, Standard VGA or Basic Display adapters) and stops if it finds one. Gen says it also avoids systems in CIS and Baltic countries.

Browser theft has to get past App-Bound Encryption, the protection Chrome added on Windows in 2024 so that only Chrome itself can unwrap the key that encrypts its cookies and passwords. Chrome still needs that key in memory while it runs. Warden scans the browser's memory for the tag v20, which marks the v20_master_key entry, checks which nearby 32-byte buffers look like the key, then hijacks one of Chrome's own threads to call CryptUnprotectMemory from inside the process, where the call succeeds. Gen notes the method resembles what Vidar and Remus do.

Stolen data goes out over HTTPS in a custom compressed binary format to one of one to five command and control domains per build. The malware can also download more payloads with certutil.exe -urlcache -split -f into %TEMP% and run them hidden, which is why one Warden infection can turn into a different infection later.

What it takes from AI tools

Gen lists the AI data Warden goes after as access and refresh tokens, credentials stored in Model Context Protocol (MCP) configurations, prompt histories, conversation databases and project traces. MCP is the standard agents use to connect to outside tools such as a database, a ticket system or a cloud account, and its config files often hold the API keys for those systems in plain text.

Hudson Rock, which tracks stealer logs, published logs from Warden infections on October 7. One contained a stolen .claude.json file with a primaryApiKey value and OAuth account data for an Anthropic account. Others held SSH config and known_hosts files, which tell an attacker which servers the developer connects to, and data from GitHub and Discord. A refresh token is worse than a session cookie in one way: it is designed to mint new access for weeks, so it keeps working after the short-lived token beside it expires.

Where the files live matters for defence. According to Anthropic's documentation, Claude Code keeps its credentials in the macOS Keychain, but on Windows it writes them to %USERPROFILE%\.claude\.credentials.json, protected only by the user profile's file permissions. Any process running as that user, Warden included, can read it.

What attackers are doing

The authors told interviewers that development started in early 2026 and the service went public on July 21. KrakenLabs logged its first forum advert on July 24, which then claimed more than 330 target applications. Gen first saw builds in early May, with a sharp rise in early August. Version 1.9 now advertises all Chromium and Gecko browsers, more than 200 wallet extensions and more than 360 other applications in 13 categories. It also dropped Windows 7 and raised prices, with an Enterprise tier at $1,500 a month.

The authors claim about 110 active customers, a figure Gen and Hudson Rock both report as the sellers' own. Hudson Rock says its data shows tens of thousands of compromised machines. Gen also concluded that Warden is the family it had earlier tracked as CallbackBeaver, based on the Rust code, the obfuscation, the loader and matching clipper settings. The clipper covers ten currencies, including Bitcoin, Ethereum, Solana and Litecoin.

What to do

  1. Hunt with Gen's indicators. Gen publishes Warden hashes and roughly 50 C2 domains at github.com/gendigitalinc/ioc in the WardenStealer folder. Load them into your EDR and DNS or proxy blocklists, and search past DNS logs for hits.
  2. Look for the loader's behaviour. In Sysmon, Event ID 8 (CreateRemoteThread) with explorer.exe as the target and an unsigned process from a user-writable folder as the source is a strong lead. Event ID 10 (ProcessAccess) where a process other than the browser opens chrome.exe or msedge.exe with memory write rights fits the cookie key theft. Event ID 1 or Security event 4688 with certutil.exe and -urlcache catches the follow-on download.
  3. If a machine is infected, re-image it. The loader can install more malware, so a cleaned host cannot be trusted. Do the rotation below from a different device.
  4. Revoke what agents and browsers held. End all sessions for Claude, ChatGPT (Codex signs in with it), Cursor and Grok from each service's account settings, then sign in again; a local logout does not cancel a token that has already been copied. Replace Anthropic and OpenAI API keys, every key written into an MCP config, GitHub personal access tokens and SSH keys. Move funds out of any wallet used on the machine.
  5. Store fewer secrets in plain files. For Codex, set cli_auth_credentials_store = "keyring" in ~/.codex/config.toml so it uses Windows Credential Manager instead of ~/.codex/auth.json. For Claude Code on Windows, turn on object access auditing (Security event 4663) for .claude\.credentials.json and alert on readers other than Claude Code. Feed MCP secrets from a secrets manager or environment at launch rather than writing them into the config.
  6. Cut the delivery paths. Block cracked software and game cheats on work devices with application control, and consider hiding the Run box with the Group Policy setting "Remove Run menu from Start Menu" for staff who never need it, which breaks the usual ClickFix instruction.

The wider lesson

Agent credential files and MCP configs deserve the same care as an SSH private key: know which machines have them, keep the tokens in them scoped, and put them on the stealer incident checklist.

Endpoint hunting and stealer response sit in our security operations work, and locking down how developer tools store credentials is part of safeguarding and hardening. If you want help checking whether Warden has reached your developers, open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Gen Threat Labs, Gen Threat Labs on AI agent data, Hudson Rock, GBHackers, Cybersecurity News, Cyberpress, Gen IOC repository, Claude Code authentication docs, OpenAI Codex authentication docs.

Back to the blog, or read this post on the full site.