🎯 Threat Intelligence
Okta's threat intelligence team analyzed a 7GB infostealer dump released on a Telegram channel, finding 555 JWTs for AI service authentication and 1,843 unexpired tokens across 5,871 infected machines in 162 countries.
🔹 Technical Details
The dump contained 44,791 unique JWTs, of which 555 were likely related to AI service authentication. Affected services include Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
Okta also identified 2,937 JWE (JSON Web Encryption) data structures. Most were set by OpenAI, which uses NextAuth.js for authentication. While JWEs can only be decrypted by the key holder, they can still be replayed for account access as long as they remain unexpired.
On the day of release, 1,843 JWTs and JWEs were unexpired. 17.7% of the 44,791 JWTs contained plaintext PII including names, phone numbers, and email addresses.
🔹 Attack Chain Analysis
- Initial Access: Infostealers (Lumma Stealer, Vidar) infect endpoints via standard delivery methods
- Credential Harvesting: Stealers collect credentials, session tokens, and API keys from compromised machines
- Distribution: Stolen data sold on underground forums as stealer logs
- Session Replay: Threat actors replay valid JWTs/JWEs to access AI services without authentication, bypassing MFA
As Jeremy Kirk, director of threat intelligence at Okta, noted: "Once successfully replayed, a threat actor is effectively logged in to an LLM service without actually logging in."
🔹 Detection Considerations
Okta states that use of these stolen tokens "makes abuse more challenging but not impossible to detect." Session replay attacks may not work universally, as some services implement additional session validation. The plaintext PII in JWTs does not expire and directly links users to specific services, creating persistent risk for social engineering and phishing campaigns.
🔹 Key Observations • 555 JWTs specifically for AI service auth out of 44,791 total • OpenAI's NextAuth.js implementation generates JWEs that are replayable despite encryption • 17.7% of JWTs expose plaintext PII that never expires • The 7GB dump spanned 162 countries and 5,871 machines
🔹 References
Source: Okta Threat Intelligence report shared with The Hacker News. The date of August 2 listed in the source may contain a typographical error.
🔹 infostealer #JWT #MFA #threataintel #Okta
🔗 Source: https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html?m=1