Unit 42 reports a surge in AI token jacking, where attackers steal legitimate API keys to rack up massive usage charges through transfer stations and gray-market proxy services. The article explains how stolen tokens, compromised developer accounts, and supply-chain infections like Shai-Hulud and Miasma fuel the abuse, while recommending spending limits, short-term tokens, and AI gateway controls. #ShaiHulud #Miasma #newapi #oneapi #PaloAltoNetworks
Keypoints
- Unit 42 says AI token jacking is causing significant financial losses by exploiting stolen API keys used for legitimate AI platform access.
- Attackers profit by using or reselling stolen tokens, often before victims notice because billing is typically cyclical.
- Gray-market “transfer stations” sell discounted access to frontier AI models through proxy services such as new-api and one-api.
- Threat actors obtain tokens through phishing, infostealers, compromised developer accounts, exposed repositories, improperly secured file shares, and poisoned npm packages.
- Supply-chain campaigns such as Shai-Hulud and Miasma are highlighted as especially dangerous sources of stolen credentials.
- Some cases led to nearly one million dollars in charges, and transfer stations can generate hundreds of thousands of dollars in fees quickly.
- Mitigations include spending limits, alerting on anomalies, reviewing privileged accounts, using short-term bearer tokens, AI gateways, and tighter development environment controls.
MITRE Techniques
- [T1552.001 ] Credentials In Files – Attackers steal access keys from improperly secured file shares or code repositories [‘They can also mine keys from improperly secured file shares or code repositories.’]
- [T1195.001 ] Supply Chain Compromise: Compromise Software Dependencies and Development Tools – Poisoned npm packages are used to steal credentials and access tokens from developers [‘attackers have stolen these keys using poisoned, self-propagating npm packages downloaded by unsuspecting developers’]
- [T1556 ] Modify Authentication Process – Attackers disable critical usage alerts and logging on compromised developer accounts to reduce detection [‘Removing billing limits’, ‘Disabling critical usage alerts and logging’]
- [T1078 ] Valid Accounts – Stolen legitimate developer API keys and accounts are reused for unauthorized access to AI services [‘criminals gaining access to API keys used by legitimate developers’]
- [T1566 ] Phishing – Compromised developer accounts are also obtained through phishing campaigns [‘through phishing campaigns’]
- [T1040 ] Network Sniffing – Transfer stations monitor and mine sessions/prompts, exposing sensitive data from users [‘developers risk having their sessions monitored and mined for sensitive data’]
Indicators of Compromise
- [User Agent ] malicious API calls – Go-http-client/2.0,gzip(gfe)
- [IP Address ] malicious API calls – 3.235.109[.]125, 116.105.166[.]148, and other 9 items
- [IP Address ] malicious login (Credential Theft) – 117.72.74[.]48, 207.246.106[.]162, and other 2 items
- [Domain ] transfer station infrastructure – amutes[.]com, abb1[.]life
Read more: https://unit42.paloaltonetworks.com/ai-token-jacking/