AI credentials are drawing criminal attention. A growing form of abuse, called AI token jacking, lets intruders take API keys and consume expensive model services on someone else’s account. The result can be a sudden bill.
The theft is not limited to a single break-in method. Attackers can obtain developer credentials through phishing, information-stealing malware, exposed file shares, public code repositories, or poisoned software packages.
A compromised key can feed an illicit proxy service that consumes paid AI capacity.
Analysts at Unit 42 identified a rising number of these cases and described losses that can become severe within minutes.
Palo Alto Networks said in a report shared with Cyber Security News (CSN) that attackers have turned inadvertently exposed credentials into nearly $1 million in charges before victims detected and contained the abuse.
A small secret can become a costly business risk. AI providers often bill after usage rather than stopping every unusual request in real time, while accounts can scale with few limits.
That delay gives criminals room to run automated workloads or sell access onward, leaving the owner responsible for spending.
An API key is a digital credential that allows software to use a service without a person signing in each time.
For large language models, charges are commonly based on tokens, small units of text processed by the model. Stolen keys therefore represent ready-made purchasing power, not just a login secret.
Unit 42 linked the activity to so-called transfer stations, gray-market services that sit between users and official AI platforms.
These services can rotate credentials, route requests, and bill customers using their own credits. Some advertise low-cost access, giving stolen keys a route to resale.
In incidents reviewed by the team, this infrastructure produced tens of millions of API calls daily, pushing fees into hundreds of thousands of dollars.
Operators need a large supply of discounted or stolen credentials to keep prices low. They may use privileged developer accounts to create keys, enable models, remove spending limits, or silence alerts.
This is why teams should treat exposed AI credentials as urgent incidents, much like the stolen Gemini key billing case, where misuse quickly produced major costs.
The report also highlights poisoned, self-spreading npm packages as an especially worrying route.
Once a developer installs one, it can steal credentials from that environment and contaminate later code releases, widening the pool of usable keys.
Recent coverage of malicious npm package theft illustrates how supply-chain infections can target developer, cloud, and AI credentials together.
Organizations have little ability to recover money after a provider bills for consumed AI resources, according to the researchers. The impact can threaten smaller firms.
Victims should review model-usage and billing records, revoke exposed keys immediately, and investigate account activity to establish when suspicious requests began.
Prevention starts with limits that match normal use. Organizations should set AI spending caps, generate alerts when use sharply exceeds the baseline, and review every privileged account able to provision resources or change billing controls.
This can reveal abnormal consumption before a monthly invoice. Teams should replace long-lived keys with short-lived bearer tokens wherever possible, and ensure each machine using AI services has a verified, managed identity.
Network boundaries around compute resources can also stop a compromised credential from being used freely from a transfer-station system. This reduces exposure and attacker operating time.
Development environments need the same attention. Review dependencies and build pipelines, block untrusted package releases, scan repositories and shared storage for secrets, and rotate exposed credentials.
The API keys exposed online tools report and coverage of malicious IDE extension theft show how routine workflows can expose secrets.
Ultimately, token jacking succeeds when a powerful credential is left unguarded and usage is left unchecked.
Fast key revocation, realistic spending controls, tighter access permissions, and careful software supply-chain practices can stop charges before they escalate.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| User-Agent | Go-http-client/2.0,gzip(gfe) | Associated with malicious API calls |
| IP address | 3.235.109[.]125 | Malicious API calls |
| IP address | 116.105.166[.]148 | Malicious API calls |
| IP address | 172.96.142[.]186 | Malicious API calls |
| IP address | 38.46.219[.]166 | Malicious API calls |
| IP address | 38.46.219[.]163 | Malicious API calls |
| IP address | 38.46.219[.]162 | Malicious API calls |
| IP address | 23.237.196[.]170 | Malicious API calls |
| IP address | 15.204.106[.]173 | Malicious API calls |
| IP address | 104.243.42[.]117 | Malicious API calls |
| IP address | 198.255.70[.]210 | Malicious API calls |
| IP address | 47.88.103[.]81 | Malicious API calls |
| IP address | 47.251.72[.]239 | Malicious API calls |
| IP address | 117.72.74[.]48 | Malicious login and credential theft |
| IP address | 207.246.106[.]162 | Malicious login and credential theft |
| IP address | 23.236.182[.]215 | Malicious login and credential theft |
| IP address | 95.214.112[.]26 | Malicious login and credential theft |
| Domain | amutes[.]com | Transfer station infrastructure |
| Domain | abb1[.]life | Transfer station infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…