Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
The Hacker News published a report titled "Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA." According to the source, infostealer logs contain AI tokens that are replayable and can be used to bypass multifactor authentication. The report describes the tokens as exposed through infostealer logs, the collections of stolen credentials and session data gathered by credential-stealing malware. The source does not identify which AI services, token types, or vendors are involved, nor does it state how many tokens were found or which infostealer families captured them. It also does not describe remediation steps, detection guidance, or whether the affected tokens have been revoked. The excerpt provides no timeline beyond the publication date of 2026-09-09 and no technical detail on how the replay works. The central claim is limited to the presence of replayable AI tokens in infostealer logs and their ability to bypass MFA.
The report indicates that AI tokens captured by infostealers can be replayed to bypass MFA, a risk developers should weigh when handling AI service credentials.