Identity, not infrastructure, has become the softest target in enterprise security. New research from Wiz, drawing on data from NordStellar, shows that infostealer malware cheap, industrialized, and ruthlessly efficient is now a leading initial access vector into cloud, code, and AI environments, quietly bypassing defenses that were never designed to stop a stolen session token.
Infostealers like Lumma, RedLine, and Vidar are rented out for a few hundred dollars a month through mature Malware-as-a-Service platforms.
These three families alone account for 85.7% of detected infections, a striking sign of how commoditized the ecosystem has become.
Infostealer Malware Breaches Cloud, Code & AI Systems
Once malware harvests credentials from an infected endpoint, it sells the data through underground marketplaces, often via Initial Access Brokers who validate and resell high-value logs to ransomware operators. The gap between a single phishing click and a corporate cloud breach can be as short as hours.
The analysis found AWS credentials made up 46% of all compromised secrets, followed by GCP at 13%. Attackers target long-term IAM access keys and cached session cookies stored in predictable local paths, files like ~/.aws/credentials or the SSO cache directory, where OIDC tokens can remain valid for up to 90 days.

In Azure environments, stolen accessTokens.json or MSAL cache files can hand attackers direct access to Azure Resource Manager APIs, no portal login required. In GCP, long-lived OAuth refresh tokens stored in credentials.db rarely expire unless explicitly revoked, giving attackers a near-permanent foothold.
GitHub credentials are now targeted by roughly half of all infostealer families, making them the fourth most-harvested secret type overall. Compromised Personal Access Tokens, SSH keys, and session cookies expose not just source code but CI/CD secrets and deployment pipelines.
GitLab shows a similar pattern, with runner tokens and session cookies enabling attackers to hijack build pipelines outright. Newer threats like the Miasma supply-chain malware skip phishing entirely, hijacking legitimate open-source packages to inject credential-stealing code directly into developer environments.
AI platforms account for 5% of stolen secrets, dominated by OpenAI API keys. Beyond financial theft and reselling stolen compute on illicit LLM marketplaces, attackers can hijack ChatGPT session cookies to access chat histories containing proprietary code and business strategy.
Anthropic’s Claude Code is emerging as a fresh target too, with malware scraping OAuth tokens from ~/.claude/.credentials.json or memory-resident API keys, granting access to conversation history and connected MCP servers.
Notably, mainstream post-exploitation toolkits like PEASS-ng now include detection rules specifically for AI assistant credentials, a clear signal that AI secrets have entered the standard attacker playbook.
What makes this trend dangerous isn’t sophistication; it’s scale and simplicity. A single infected developer laptop, often a personal device running trojanized game files like Roblox.exe, can yield credentials cascading across AWS, GitHub, and OpenAI accounts simultaneously.
As organizations rush to adopt AI coding assistants and agentic workflows, the attack surface is expanding faster than most identity governance programs can keep pace with.
Security teams should treat local credential caches, AWS SSO tokens, Azure MSAL caches, and Claude Code OAuth tokens with the same urgency as production secrets, enforcing short-lived tokens, keyring-based storage, and aggressive session revocation.
In an economy where a $200-a-month malware kit can unlock an entire cloud tenant, credential hygiene isn’t optional infrastructure hardening; it’s the new perimeter.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.