Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
AI Summary
Unit 42 has identified a growing threat called 'token jacking,' where cybercriminals steal API keys (tokens) used to access AI platforms, leading to massive financial losses due to unmonitored usage. These stolen tokens are often funneled into 'transfer stations'—gray-market services that resell discounted AI computing capacity—using proxy platforms like new-api or one-api. Attackers obtain tokens via phishing, information stealers, or malicious npm packages such as Shai-Hulud and Miasma, which self-propagate and harvest credentials from development environments. The stolen tokens are then used to generate millions of API calls, resulting in hundreds of thousands of dollars in unauthorized charges before detection.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 18 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 3[.]235[.]109[.]125 | Details → |
| IP | 116[.]105[.]166[.]148 | Details → |
| IP | 172[.]96[.]142[.]186 | Details → |
| IP | 38[.]46[.]219[.]166 | Details → |
| IP | 38[.]46[.]219[.]163 | Details → |
| IP | 38[.]46[.]219[.]162 | Details → |
| IP | 23[.]237[.]196[.]170 | Details → |
| IP | 15[.]204[.]106[.]173 | Details → |
| IP | 104[.]243[.]42[.]117 | Details → |
| IP | 198[.]255[.]70[.]210 | Details → |
| IP | 47[.]88[.]103[.]81 | Details → |
| IP | 47[.]251[.]72[.]239 | Details → |
| IP | 117[.]72[.]74[.]48 | Details → |
| IP | 207[.]246[.]106[.]162 | Details → |
| IP | 23[.]236[.]182[.]215 | Details → |
| IP | 95[.]214[.]112[.]26 | Details → |
| Domain | amutes[.]com | Details → |
| Domain | abb1[.]life | Details → |