Warden Stealer: Gen Threat Labs says a fast-growing Rust malware-as-a-service now steals tokens and data from AI coding agents such as Claude, Codex, Grok and Cursor, alongside browser passwords, cookies and crypto wallets
Gen Threat Labs (Gen Digital) published an analysis on 8 October 2026 of Warden Stealer, a Windows information stealer sold as malware-as-a-service and written in Rust. First builds appeared in early May 2026 and it has been advertised on Russian-language forums since August; within months it became one of the most common stealers in Gen's user base. Gen previously tracked it as CallbackBeaver and has now linked it to the Warden brand. Each operator configures their own build, targets and command-and-control servers, and the kit includes its own loader and a clipboard clipper that swaps copied cryptocurrency wallet addresses. Builds are heavily obfuscated and re-shaped ('morphed') to beat signature detection, and Gen documents how it bypasses Chrome's Application-Bound Encryption. Beyond browsers, wallets, messengers, password managers and VPN clients, many builds collect configuration files and local data from AI assistants and coding agents, which can hold access and refresh tokens, MCP credentials, prompt histories and project traces; version 1.9, announced on 29 September 2026, made AI coding agent token theft an official feature. Operators spread it through ClickFix fake-verification pages, malicious ads, cracked software and fake game cheats (per Cyber Security News). Primary: Gen Threat Labs; wire: Cyber Security News.
- Product
- Windows 8 to 11 endpoints — browsers, crypto wallets and AI coding agent data (Claude, Codex, Grok, Cursor)
- Versions
- n/a — malware family (v1.9 adds official AI agent token theft)
- Exploited in Australia?
- unknown
- Patch to
- Block ClickFix-style 'paste this command' prompts through user training and by restricting the Run dialog and PowerShell for standard users; ban cracked software and game cheats on work devices. On a suspected infection, revoke and reissue AI agent, MCP, GitHub and cloud tokens as well as browser sessions and passwords, not just passwords.
Primary: Gen Threat Labs — Warden Stealer: from attribution to a technical breakdown of a Rust infostealer (8 Oct 2026) · Cyber Security News — Warden Stealer spreads through ClickFix, malvertising, cracked software and game cheats (9 Oct 2026)
