// 2 ZERO-DAY · 5 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
Infostealer malware, distributed through a mature and accessible criminal economy, has become the primary initial access vector for compromising cloud environments, development platforms, and AI services. A Wiz analysis published September 25, 2026, shows three families — Lumma C2, RedLine, and Vidar — account for 85.7% of incidents detected by the NordStellar platform. The paradox: these attacks do not break modern authentication; they steal it after it happens, making developers' personal devices — often less protected than corporate assets — the decisive battleground.
{"main_topic":"infostealer","topics":["cybersecurity","infostealer","cloud","ai","malware"]}

Infostealer malware, distributed through a mature and accessible criminal economy, has become the primary initial access vector for compromising cloud environments, development platforms, and AI services. According to analysis published by Wiz on September 25, 2026, three families — Lumma C2, RedLine, and Vidar — account for 85.7% of incidents detected by the NordStellar platform. The paradox is that these attacks do not breach modern authentication; they steal it after it occurs, making developers' personal devices — often less protected than corporate assets — the decisive battleground.

Key Takeaways
  • Lumma C2, RedLine, and Vidar represent 85.7% of infostealer incidents according to Wiz/NordStellar data
  • AWS accounts for 46% of compromised secrets, with SSO tokens lasting up to 90 days in local cache
  • AI platforms already represent 5% of stolen secrets, dominated by OpenAI API keys
  • The TeamPCP group validated stolen credentials with TruffleHog within hours and began AWS discovery within 24 hours

Post-Authentication Theft: When MFA and SSO Become Irrelevant

The core attack mechanism is not credential cracking but credential capture at their most vulnerable moment: after authentication. Infostealers steal OIDC, SSO, and OAuth session tokens generated after MFA completion, allowing attackers to impersonate legitimate users without ever touching authentication systems. As Wiz Research observes: "A single valid session token for a corporate system, especially if the user has high privileges or access to sensitive information, can enable access to many resources in the target organization's cloud environment".

The temporal persistence of these tokens amplifies risk. OIDC SSO tokens, stored in ~/.aws/sso/cache/, typically last up to 90 days. This window enables continuous "minting" of fresh credentials by the attacker. STS tokens in ~/.aws/cli/cache/ have shorter lifespans, 1 to 12 hours, making them less attractive to Initial Access Brokers unless sold immediately. Platform distribution shows sharp concentration: AWS collects 46% of compromised secrets, GCP 13%, GitHub — with App Tokens, OAuth, and PATs — roughly 10%.

MaaS Industrialization and Attack Time Compression

The economy surrounding infostealers has reached maturity levels comparable to legitimate software. Illicit marketplaces function as e-commerce platforms: the malware is the product, stolen credentials are the merchandise, and Initial Access Brokers are the distributors. The CISA AA23-320A advisory documents how Scattered Spider purchases employee and contractor credentials on marketplaces like Russia Market, highlighting that the criminalized supply chain has become the preferred channel for initial access.

Monetization speed is the parameter that most disrupts the traditional defensive paradigm. In the TeamPCP case, documented by Wiz, stolen credentials were validated with TruffleHog within hours of theft. AWS environment discovery began within 24 hours. Attackers created pull requests with malicious GitHub workflows, executing code and deleting logs to cover tracks. This sequence renders response windows based on weekly or monthly detection ineffective.

"These tools are designed for one purpose: rapid, stealthy data harvesting. They execute, scrape credentials, and exfiltrate data in seconds, often from devices that have up-to-date antivirus software" — Wiz Research

From Cloud to AI: Blast Radius Expansion

Credential theft no longer stops at traditional cloud platforms. NordStellar identifies over 400 distinct types of non-credential secrets stolen, and 5% of total compromised secrets involve AI platforms, dominated by OpenAI API keys. The dossier does not specify whether these keys were actually used to access historical chat logs containing sensitive corporate data; the potential impact, however, exposes unconventional data exposure risks, where models and corporate conversations become tradeable commodities.

Real-world cases corroborate the theoretical model. Miasma compromised 32 npm package releases with approximately 80,000 average weekly downloads, adding in one variant — dubbed Mini Shai-Hulud — collectors for GCP and Azure identities alongside the original secrets. JINX-0164 traversed the full chain from social engineering to macOS infostealer to CI/CD compromise and code distribution, though it is unclear whether it distributed malware via npm beyond the documented @velora-dex/sdk case. The extent of these patterns across threat actors beyond the original ones is not quantifiable.

The Gap Between Corporate Policy and Developer Shadow IT

Wiz's analysis highlights a structural discrepancy: corporate security policies are designed to protect managed assets, while developers operate daily on personal machines with privileged access to repositories, cloud environments, and AI services. These endpoints — often running up-to-date antivirus, as documented in the analyzed cases — are not equivalent to corporate assets in attack surface, but they are in potential impact.

The 90-day persistence of OIDC tokens in local cache turns every compromised endpoint into a potential source of continuous valid credential regeneration. CISA has documented APTs using forged OAuth tokens for lateral movement in Microsoft cloud, demonstrating that post-compromise abuse tactics are established in contexts beyond infostealers. Advisory AA21-008A, specific to the SVR APT and the SolarWinds incident, describes how actors "used on-premises access to manipulate and bypass identity controls and multi-factor authentication".

Why It Matters

The dossier does not specify the exact scope of the Wiz/NordStellar data: it is unclear whether the reported numbers are global or limited to Wiz's customer dataset. The actual frequency of 90-day OIDC token resale versus preventive revocation is not documented. The brief does not list specific remedial measures or operational actions by the primary source.

The brief does not specify the exact nature of data exposed by stolen AI keys, nor does it document whether code hosting platforms have implemented additional controls for anomalous session detection. It is not confirmed whether the described session hijacking tactics have been massively detected on endpoints with hardware MFA rather than software-based implementations.

The brief also does not clarify whether the MaaS economy is evolving toward vertical specialization by sector (fintech, healthtech, AI labs) or still maintains a horizontal auction-based sales model. The discrepancy between TeamPCP's speed (hours/days) and typical enterprise detection windows (days/weeks) remains the critical gap the dossier identifies but does not quantify in terms of prevalence.

The industrialization of initial access has lowered the barrier to sophisticated offensive capabilities. The question is no longer whether an attacker can bypass perimeter defenses, but how quickly they can convert a development endpoint into persistent access to an entire cloud ecosystem. In this scenario, the distinction between corporate asset and developer shadow IT is no longer operational: the perimeter itself has shifted, and defensive measures have not yet followed.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. wiz.io
  2. cisa.gov