The Infostealer That Reads Your Agent Config: Warden Stealer Harvests Claude, Codex, Grok, and Cursor Tokens
On 8 October 2026, Gen Threat Labs researchers Vojtěch Krejsa and Jan Rubín published a 33-minute technical breakdown that does two things at once: it attributes a Rust infostealer they had been tracking as CallbackBeaver to the malware-as-a-service brand Warden Stealer, and it documents that stealer as one of the first infostealer families to go after AI agent data as a first-class target — configuration files and local data belonging to Claude, Codex, Grok, and Cursor. Depending on the agent, that means access and refresh tokens, credentials stored in MCP configurations, prompt histories, conversation databases, and traces of the projects a developer has been working on. As Gen puts it, that haul gives an attacker both the means to access an account and the context needed to understand what valuable data sits behind it.
The timeline matters. Warden has been promoted on underground forums only since August 2026, with first builds tracked to early May 2026 — yet Gen already ranks it among the most prevalent infostealers in its user base, alongside Vidar, Amatera, and Remus. The authors claim about 110 active customers. AI agent collection started as custom operator rules, then became official product: version 1.9, announced 29 September 2026, formally advertised the collection of AI coding-agent tokens — and raised prices sharply at the same time, with Premium jumping from $499 to $800 a month and a new $1,500 Enterprise tier. Somebody is paying for this capability.
Why Warden is not just another stealer build
Most MaaS infostealers ship a payload and leave operators to handle delivery and evasion. Warden bundles its own dedicated loader and a built-in cryptocurrency clipper — a combination Gen calls uncommon, and a plausible explanation for the rapid uptake. The clipper originally covered six networks (BTC, ETH, TRX, XMR, SOL, TON) and added four more in v1.7 (LTC, XRP, ADA, BCH); Gen verified the exact network list — in the same order — inside extracted build configurations, which is part of the attribution case. The loader, which Gen assesses with high confidence is built in-house, runs in three modes: injection (the default — reconstruct the payload in memory and inject it into a living process, currently whatever owns the Shell_TrayWnd taskbar window, normally explorer.exe), sideload (DLL next to a legitimately signed EXE), and standalone.
The evasion engineering is the product's headline feature — marketed, in Gen's translation, as the “only true morpher on the market (not just an obfuscator), built upon AST code parsing and LLVM IR passes.” Each build uses its own custom Base64-like alphabet (not mere permutations — different character sets entirely) plus a custom LZSS layer for strings and payload blobs, lazy string decoding, dynamic API resolution, indirect control flow, TLS-callback-driven constant recovery (the namesake of the old CallbackBeaver label), MBA expressions, and opaque predicates. Loader binaries are additionally inflated with massive PE overlays designed to make scanners, sandboxes, and cloud upload pipelines choke on file size. Anti-VM checks span SMBIOS firmware tables, a 27-signature cpuid blacklist plus substring markers, Virtio-prefixed uninstall entries, and virtual display adapters — and on detection the malware pops a Russian-language joke dialog titled DEBUG and aborts its reporting worker.
The ABE bypass, and what it says about browser-data theft in 2026
Chromium's Application-Bound Encryption (ABE) was supposed to raise the cost of cookie and password theft. Warden's bypass is a three-step routine Gen describes as a novel combination of techniques seen in Vidar and Remus, implemented independently: scan the browser's memory for the four-byte v20\x00 tag that marks the v20_master_key entry in Chromium's KeyRing map, validate candidates against the expected in-memory layout of the key vector (handling both pointer-based and size-based libc++ representations), then hijack a browser thread to run a shellcode stub calling CryptUnprotectMemory with CRYPTPROTECTMEMORY_SAME_PROCESS and poll the buffer for changed bytes. The validation heuristics — pointer alignment, a 32-byte size check, capacity bounds — are the kind of detail that only comes from reading the implementation rather than the marketing. The defensive takeaway is blunt: ABE forces stealers to do in-process surgery, and the current generation of stealers does it routinely.
The agent-data angle is the story
Gen is explicit that this trend did not start with Warden — their 8 September 2026 post, “Infostealers Have Found a New Target: Your AI Agent,” found agent-data collection rules across the landscape, naming Amatera, Remus, and what they then called CallbackBeaver. What changed is institutionalisation: an operator curiosity became a versioned, advertised, price-hiked feature within weeks, and it now appears in a substantial subset of Warden builds. The stealer's C2 protocol — HTTPS, per-build XOR, LZNT1 framing with a 16-byte build marker, 1–5 hardcoded fallback domains, system fingerprinting on registration, dynamic per-build configuration — also supports downloading and executing second stages via certutil.exe into %TEMP% launched hidden through COM ShellExecute. Gen publishes an extensive IoC list (hashes, C2 domains such as backtoblack7[.]com, skibidistealer[.]team, and web03-azureupdate[.]com) on its GitHub.
Two clarifications the research supports and we endorse. First, this is not a vulnerability in Claude, Codex, Grok, or Cursor — it is endpoint theft after a Windows host is compromised, delivered through ClickFix lures, malvertising, cracked software, and fake game cheats. Patching your agent does nothing; cleaning the endpoint does everything. Second, the proximity to our recent coverage is the point: the Tensorlake npm compromise poisoned the machines people build agents on, the GhostAction burst planted credential stealers in tens of thousands of repos — and Warden harvests what those footholds leave behind: the tokens, MCP credentials, and conversation histories sitting in plaintext on developer workstations.
What to do
- Treat AI agent config directories as credential stores.
~/.claude, Codex/Cursor config paths, and MCP server configs hold tokens, refresh tokens, and saved credentials. Restrict permissions, exclude them from backups that leave the trust boundary, and never paste their contents into tickets, gists, or shared docs. - Scope and rotate what the stealer would find. Short-lived tokens, least-privilege API keys per project, and MCP servers that reference secrets from a vault rather than embedding them turn a total compromise into a bounded one. Rotate anything that lived on a host you cannot vouch for.
- Hunt the loader's behaviours, not its hash. Morphing defeats static signatures by design. Watch for
certutil.exe -urlcachedownloads to%TEMP%, remote-thread injection intoexplorer.exe, oversized binaries with giant overlays, and outbound HTTPS to newly registered domains. - Assume breach cleanup for infected developer machines. A stealer that exfiltrates prompt history and project context compromises more than credentials — it hands the attacker a map of your codebase, infrastructure, and internal hosts. Reimage, rotate every secret the host ever touched, and review what the stolen context exposes.
Verification note: the attribution (CallbackBeaver to Warden), timeline (forum promotion since August 2026, first builds early May, public availability 21 July 2026, v1.9 AI-token announcement 29 September 2026), pricing, loader modes, obfuscation and anti-VM details, ABE bypass mechanics, C2 protocol description, and IoC references were read first-hand from the Gen Threat Labs blog HTML (Krejsa and Rubín, 8 October 2026) fetched on 10 October 2026. Distribution vectors (ClickFix, malvertising, cracked software, game cheats) and the early-May-to-August activity arc are from Cyber Security News and GBHackers coverage of the same research, fetched the same day, and are attributed accordingly. The September precursor post is Gen’s own linked prior work. We tested nothing and exploited nothing.
Sources:
- Gen Digital — Warden Stealer: The Rapid Rise of an Infostealer with an Appetite for AI Agent Data (8 October 2026; primary research, attribution, technical breakdown, IoCs)
- Gen Digital — Infostealers Have Found a New Target: Your AI Agent (8 September 2026; precursor landscape analysis)
- Cyber Security News — Warden Stealer Spreads Through ClickFix, Malvertising, Cracked Software and Game Cheats (9 October 2026; distribution vectors)
- GBHackers — Warden Stealer Malware Targets Claude, Codex, Grok and Cursor to Steal AI Agent Data (9 October 2026)