Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
SpecterOps has released Blacklight, an open-source toolkit that identifies local artifacts from AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI, which can expose authentication data, session history, project details, and connected services. AI agents are increasingly used to write code, troubleshoot problems, run commands, inspect repositories, and interact with cloud resources. These […] The post Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing To
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeAI
Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data
By Abinaya
August 13, 2026
SpecterOps has released Blacklight, an open-source toolkit that identifies local artifacts from AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI, which can expose authentication data, session history, project details, and connected services.
AI agents are increasingly used to write code, troubleshoot problems, run commands, inspect repositories, and interact with cloud resources.
These tools improve productivity, but they also create a new endpoint security concern. Their local files may contain sensitive information that attackers could use after gaining access to a workstation.
Blacklight helps authorized security teams understand this emerging exposure. Rather than immediately collecting every file, the toolkit first identifies installed AI agents.
It ranks the most useful artifacts for review. This approach is intended to reduce unnecessary data collection and help defenders understand what needs protection.
Blacklight Toolkit
The most sensitive artifacts are authentication files. Codex files such as .codex/auth.json and Claude Code credential files may contain access tokens, refresh tokens, account identifiers, session metadata, and OAuth-related information.
A valid access token could allow an attacker to impersonate an authenticated user session. Refresh tokens may also provide longer-term access if they remain valid.
Decoded access token revealing authentication mechanism and email (source: Specterops )
Configuration files can reveal another layer of risk. Settings may show which models a user runs, trusted projects, command approval settings, sandbox rules, environment variables, and MCP server configurations.
In some cases, environment variables may include API keys, cloud credentials, or connection information for external model providers. This information can help an attacker identify trusted services and possible paths into other systems.
Session transcripts are also valuable. AI agent chat history can reveal what a user is working on, internal file paths, repository names, debugging output, deployment instructions, internal URLs, hostnames, and commands.
Even when sessions do not contain raw credentials, they can reveal business context and operational intent. An attacker could use that information to identify important infrastructure, active projects, or possible follow-on targets.
Blacklight Scout provides endpoint discovery across Windows, macOS, and Linux. Its quieter loaders perform filesystem triage and report discovered agent roots, valuable paths, file size, and recency without reading artifact contents.
Blacklight session analysis report artifacts (source: SpecterOps)
Windows executables can perform deeper metadata analysis, but they are designed not to print secrets, identities, session text, or endpoints.
For deeper investigation, selected files can be collected and processed offline with the blacklight sessions command. The analysis can identify supported agent files, parse recognizable formats, generate redacted indicators, and create ranked reports.
The toolkit can also prepare artifacts for tools such as Nemesis and TruffleHog, which can perform more extensive secret scanning. For defenders, Blacklight includes osquery configurations and SIEM guidance for inventorying agent artifacts and monitoring changes.
On Windows, the project recommends Security Event 4663 with Audit File System enabled and appropriate SACLs applied to high-value paths.
On macOS and Linux, defenders can use file event telemetry. However, monitoring must be carefully tuned, as it can generate significant volume.
The SpecterOps research highlights a growing reality for enterprise security teams: local AI agents should be treated like browser profiles, cloud CLI configurations, shell history, and other valuable endpoint data stores.
Organizations should inventory AI agent use, restrict access to local profile directories, monitor reads of credential files, review trusted-project settings, and establish retention policies for sessions. As developers rely more heavily on AI agents, protecting their local artifacts will become an important part of endpoint defense.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Trump Signs Memo Authorizing Private Firms for Cyber Operations Against Foreign Criminals
Adobe
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Cyber Security
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Cyber Security
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
Cyber Security News
Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?