Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stations

Token Jacking (TL-2026-1911), also tracked as Token Jacking, is a high-severity supply-chain compromise, first published 2026-08-06. It has no confirmed attribution, affects npm (OpenJS Foundation) npm registry supply chain, maps to 19 MITRE ATT&CK techniques (T1027, T1036, T1053.005), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1911

Threat ID
TL-2026-1911
Also known as
Token Jacking, LLMjacking, AI API Token Resale, Transfer Station / Relay Market Economy
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-08-06
Last reviewed
2026-08-06
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, cloud, ai, finance
Target regions
Global, Asia, North America, Europe
Detection rules
9
Indicators of compromise
30

Malware and tooling in Token Jacking

Malware and tooling: Miasma, Shai-Hulud, Cobalt Strike, Miasma RAT, new-api, one-api

Token jacking is a criminal economy in which attackers steal AI API keys and tokens from legitimate developers — via phishing and infostealer-harvested privileged accounts, dark-web access brokers, keys exposed on file shares/code repos, and poisoned self-propagating npm packages (Shai-Hulud, Miasma) — then resell programmatic AI access through gray-market 'transfer stations' built on the open-source new-api/one-api gateways. Compromised accounts are used to create keys, provision models, remove billing limits, and disable usage alerts/logging, driving hundreds of thousands of dollars in unauthorized AI usage and nearly a million dollars in at least one case before containment. First-party research by Palo Alto Networks Unit 42.

How Token Jacking works

Token jacking is described by Unit 42 (Palo Alto Networks) as 'a new AI-oriented spin on an old technique of stealing access to computing resources.' The offense is the theft of API keys and bearer tokens that grant programmatic access to frontier AI platforms, enabling attackers to consume AI compute capacity while the legitimate account owner is billed. Because AI billing is token-based and many providers do not cap token consumption per account, billing occurs cyclically and victims often discover the theft only after massive consumption has already accrued. Unit 42 documents cases that accumulated 'hundreds of thousands of dollars' in usage fees, and 'nearly a million dollars in charges before discovery and containment' in at least one case, with the cost able to derail budgets or force smaller businesses into bankruptcy.

Token acquisition spans multiple vectors. (1) Account compromise: attackers compromise privileged corporate developer accounts harvested through infostealer malware and phishing campaigns, then use those accounts to create new API keys, provision models, remove billing limits, and disable usage alerts and logging. Such compromised accounts are 'readily available for sale by access brokers on dark web marketplaces.' (2) Direct key harvesting: attackers mine already-provisioned access keys from improperly secured file shares and code repositories. (3) Supply-chain compromise: poisoned, self-propagating npm packages (Shai-Hulud and its Miasma variant) are downloaded by developers; once installed they infect other code the developer builds and steal credentials and access tokens from each environment, amplifying impact. The infostealer pipeline is established: in March 2026 alone, one stealer-log service indexed 3.27 billion lines of compromised credentials, with Telegram now accounting for 68% of infostealer-log distribution; logs are sold to initial access brokers who enrich and resell them at premium.

Stolen tokens feed 'transfer stations' — fly-by-night gray-market vendors selling AI computing capacity at a fraction of retail cost. Advertised on Chinese-language marketplaces such as Taobao, they 'promise access to multiple AI services with seller-issued custom credits that are purchased anonymously.' Nearly every such relay runs on one of two open-source, OpenAI-compatible gateways — new-api (QuantumNous/new-api) and one-api (songquanpeng/one-api) — which handle obfuscation, rotation and authentication of real credentials, billing, model routing, and prompt normalization. The abuse is in the inventory, not the software: channels are stocked with stolen, leaked, or pooled credentials. An independent investigation (Matt Lenhard, Vectoral) mapped the resulting four-layer economy: upstream card/account merchants, midstream account pools that aggregate dozens to hundreds of accounts and manage auth tokens and rate limits, downstream relays/transfer stations that wrap the pool in a billed product, and end users including developers, startups, and commercial model-distillation buyers. The ten highest-traffic relays tracked pull a combined 3.6 million visits per month; the cheapest, 01Now Coding, offers a 97.8% discount off official pricing (for example $3,333 of official Anthropic credit sold for ~425 RMB). Unit 42 observed exposed credentials integrated into a transfer station 'within minutes.'

Token sourcing methods identified in the underground include free-trial abuse (mass automated account creation to claim free credits), chargeback attacks (reversing charges after usage, or starting with stolen cards), prepaid-card exploitation, open-inference abuse (proxying traffic through unprotected support chatbots or exposed /api/chat endpoints), and 'denial of wallet' attacks (flooding concurrent requests purely to burn a provider's spend). Beyond pure billing fraud, relays pose a data-exfiltration risk: prompts, code context, and multi-turn reasoning traces passing through a gateway are 'pre-labeled' training data, and pool inventory includes access harvested from application-layer tools. Competing nation-states are also documented customers of transfer stations, using discounted access to frontier models for training and refining their own models at a fraction of the cost.

The supply-chain vector is the highest-blast-radius path. The Shai-Hulud worm (MITRE ATT&CK S9008), first reported September 2025 and assessed by Wiz Research as downstream of the late-August 2025 s1ngularity/Nx GitHub-token compromise, self-propagates by stealing npm tokens and GitHub Personal Access Tokens, then automatically publishing malicious versions of any accessible package. Successor waves (Shai-Hulud 2.0, Mini Shai-Hulud, the 'Miasma' family) widened targets to AI tooling — Claude and MCP configuration files, cloud secret stores, CI/CD runner memory — and shifted from post-install to preinstall and import-time execution to evade static scanning. Campaigns include the May 2025 TanStack GitHub Actions pipeline hijack (373 malicious versions across 169 packages), the May 19 @antv maintainer-account wave (639 malicious versions across 323 packages in roughly one hour), the June 1 Red Hat @redhat-cloud-services compromise (32 packages, trojanized via a compromised employee GitHub account and OIDC trusted publishing), and the July 14 AsyncAPI compromise (import-time payload delivery with resilient multi-channel C2). Unit 42 warns that the huge volume of credentials stolen in these campaigns could 'fuel transfer stations for years.'

Mitigation recommended by Unit 42 and corroborating sources includes implementing AI spending limits with alerts for deviation from baseline, reviewing privileged accounts that can provision resources or adjust spending, migrating from long-term access keys to short-term bearer tokens, deploying an AI gateway with machine authentication for real-time monitoring, enforcing network boundaries on compute resources to restrict compromised keys, and tightly managing development environments to prevent malicious packages (cooldown periods, ignoring lifecycle scripts, version pinning with npm ci, private-registry proxying, provenance verification, egress filtering, and SBOM generation).

MITRE ATT&CK techniques used in TL-2026-1911

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Persistence

T1053.005 Scheduled Task; T1098 Account Manipulation

Execution

T1059.007 JavaScript; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols

Initial Access

T1078.004 Cloud Accounts; T1195.001 Compromise Software Dependencies and Development Tools; T1195.002 Compromise Software Supply Chain; T1195.003 Compromise Hardware Supply Chain

Impact

T1496 Resource Hijacking

Credential Access

T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.005 Cloud Instance Metadata API; T1555.006 Cloud Secrets Management Stores

Lateral Movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Token Jacking

  • npm (OpenJS Foundation) — npm registry supply chain
    Vulnerable versions: Shai-Hulud, Miasma, and successor poisoned package waves
  • Multiple — Frontier AI model platforms (Claude/Anthropic, OpenAI, Google and other OpenAI-compatible APIs)
    Vulnerable versions: Accounts with long-lived API keys and no per-account token cap
  • QuantumNous / songquanpeng (dual-use gateway software) — new-api / one-api OpenAI-compatible API gateways
    Vulnerable versions: Instances stocked with stolen/leaked credentials as channels
  • GitHub — GitHub Actions CI/CD pipelines (OIDC trusted publishing, pull_request_target)
    Vulnerable versions: Misconfigured workflows leaking secrets or OIDC tokens

Remediation for Token Jacking

Immediate actions

  • Implement hard AI spending limits with alerts for deviation from baseline usage
  • Review all privileged accounts that can provision resources or adjust billing/spending
  • Rotate and revoke any exposed API keys and bearer tokens immediately
  • Block known transfer-station and malicious-C2 domains (amutes.com, abb1.life) at the perimeter
  • Enable strict usage/logging alerts so new-key creation and limit changes trigger review

Workarounds

  • Set ignore-scripts=true (or npm config set ignore-scripts true) in .npmrc to block lifecycle-script execution
  • Use version pinning (npm ci) instead of npm install in CI/CD
  • Proxy all external package registries through a private registry; never allow direct registry.npmjs.org access
  • Enforce cooldown periods blocking packages published within the last 24-72 hours

Longer-term hardening

  • Migrate from long-term access keys to short-term bearer tokens with automatic rotation
  • Deploy an AI gateway with machine authentication for real-time monitoring of token consumption
  • Enforce network boundaries on compute resources to restrict the blast radius of compromised keys
  • Tightly manage development environments to prevent malicious package installation
  • Monitor dark-web and Telegram infostealer-log channels for leaked organizational credentials

Weaknesses (CWE) in Token Jacking

CWE-522, CWE-798, CWE-200

Timeline of Token Jacking

  • s1ngularity/Nx GitHub-token compromise occurs; Wiz Research assesses the Shai-Hulud worm as directly downstream of this initial GitHub token theft that enabled npm token theft
  • Original Shai-Hulud self-propagating npm worm first reported — the first successful self-propagating attack in the npm ecosystem, stealing secrets and publishing malicious versions of accessible packages
  • Shai-Hulud 2.0 shifts to pre-install phase execution to evade static scanning, affecting 25,000+ malicious repositories across ~350 users
  • Stealer-log indexing service reports 3.27 billion lines of compromised credentials indexed in March 2026, a 14% month-over-month increase; Telegram accounts for 68% of infostealer-log distribution
  • TeamPCP (@pcpcats) impersonates @bitwarden/cli via a preinstall lifecycle script that downloads Bun to execute a 10 MB obfuscated credential stealer — first confirmed Shai-Hulud successor wave
  • Mini Shai-Hulud targets the SAP CAP ecosystem (@cap-js/sqlite, @cap-js/postgres, mbt) with ~570,000 weekly downloads, adding Claude/MCP config and Electrum wallet targets
  • TanStack GitHub Actions pipeline hijack: a pwn request against pull_request_target, cache poisoning, and OIDC token extraction from runner memory results in 373 malicious versions across 169 npm packages plus compromised PyPI packages
  • Full weaponized Mini Shai-Hulud source code published to public GitHub repositories, making the CI cache-poisoning and credential-stealer toolchain available to any actor
  • @antv wave compromises npm maintainer account 'atool', publishing 639 malicious versions across 323 packages in approximately one hour, targeting 1Password, Bitwarden, pass, and gopass password managers
  • Red Hat supply-chain attack: compromised employee GitHub account used to push trojanized packages with valid SLSA provenance to @redhat-cloud-services (32 packages, ~80,000 weekly downloads) — the 'Miasma: The Spreading Blight' credential-stealing campaign
  • Matt Lenhard (Vectoral) publishes the AI token relay-market investigation mapping the four-layer economy (card merchants, account pools, transfer stations, end users) and the 97.8% discount relay '01Now Coding'
  • AsyncAPI 'Miasma-train-p1' compromise executes at import/require time (bypassing ignore-scripts), delivering a modular RAT with resilient C2 via HTTP, Ethereum smart contracts, Nostr relays, and BitTorrent DHT
  • Relay-market measurements show the ten highest-traffic relays pull a combined 3.6 million visits per month; nearly all run on the open-source new-api or one-api gateways
  • No CVE or CISA KEV entry applies; token jacking is a credential/supply-chain fraud economy rather than a single exploitable vulnerability
  • Palo Alto Networks Unit 42 publishes the 'Token Jacking' report, documenting cases driving hundreds of thousands of dollars in unauthorized AI usage and up to nearly a million dollars before containment

Sources cited for Token Jacking

Threats related to Token Jacking

Detection coverage for TL-2026-1911

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1911 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1911

4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats