unit42 · Crawled Aug 6, 2026

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

18 IoCs 1 Malware
Read original article ↗

AI Summary

Unit 42 has identified a growing threat called 'token jacking,' where cybercriminals steal API keys (tokens) used to access AI platforms, leading to massive financial losses due to unmonitored usage. These stolen tokens are often funneled into 'transfer stations'—gray-market services that resell discounted AI computing capacity—using proxy platforms like new-api or one-api. Attackers obtain tokens via phishing, information stealers, or malicious npm packages such as Shai-Hulud and Miasma, which self-propagate and harvest credentials from development environments. The stolen tokens are then used to generate millions of API calls, resulting in hundreds of thousands of dollars in unauthorized charges before detection.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 18 extracted

Type Value Detail
IP 3[.]235[.]109[.]125 Details →
IP 116[.]105[.]166[.]148 Details →
IP 172[.]96[.]142[.]186 Details →
IP 38[.]46[.]219[.]166 Details →
IP 38[.]46[.]219[.]163 Details →
IP 38[.]46[.]219[.]162 Details →
IP 23[.]237[.]196[.]170 Details →
IP 15[.]204[.]106[.]173 Details →
IP 104[.]243[.]42[.]117 Details →
IP 198[.]255[.]70[.]210 Details →
IP 47[.]88[.]103[.]81 Details →
IP 47[.]251[.]72[.]239 Details →
IP 117[.]72[.]74[.]48 Details →
IP 207[.]246[.]106[.]162 Details →
IP 23[.]236[.]182[.]215 Details →
IP 95[.]214[.]112[.]26 Details →
Domain amutes[.]com Details →
Domain abb1[.]life Details →

MITRE ATT&CK TTPs 17 techniques