AI Token Jacking, Supply Chain Attacks Pose Datacenter Risk, ETDatacenters


Cyber attackers are increasingly targeting artificial intelligence (AI) supply chains by stealing access credentials and reselling compute power through gray-market networks, a trend that poses significant financial and operational risks for companies. Recent reports from cybersecurity players CloudSEK and Unit 42 by Palo Alto Networks detail large-scale supply chain attacks and a new threat termed “token jacking.”

Rising Threat of AI Token Jacking

Unit 42, the threat intelligence arm of Palo Alto Networks, has flagged “token jacking” as a growing concern. This process involves hackers hijacking legitimate AI access tokens and routing them to gray-market resellers to monetise stolen compute power. Cdr Raj Shastrakar (retd), director and head of Unit 42, India and SAARC, noted that this is a new spin on stealing access to computing resources, where attackers harvest long-lived credentials such as application programming interface (API) keys for AI platforms. These stolen credentials are then used to consume or resell computing power, often at a steep discount, through intermediary proxies known as “transfer stations.”The challenge in AI environments stems from the broad access organisations often grant to encourage experimentation and development. Developer accounts can carry high spending limits and extensive permissions to create API keys, provision models, or build new applications. If a privileged account is compromised, the potential impact can extend well beyond simple token usage, with companies reportedly losing millions of dollars in charges before attacks are detected and contained. Unit 42 observes this threat growing rapidly as AI adoption fuels a lucrative gray market for stolen compute access, alongside attackers becoming more effective at scaling credential theft.

Supply Chain Vulnerabilities Exposed

Separately, CloudSEK’s report detailed a large-scale supply chain attack, orchestrated by the threat actor group TeamPCP, which began in March 2026 and remains active. This incident exposed critical infrastructure keys across thousands of downstream projects, including cloud keys, repository tokens, SSH keys, Kubernetes secrets, package-publishing credentials, environment variables, and AI provider keys. CloudSEK emphasised that such stolen objects could allow attackers to move far beyond the initially affected package, as copied credentials can remain usable for weeks or months unless they are rotated and downstream activity is investigated. The report highlighted that AI systems are becoming high-value junctions between data, identity, compute, and autonomous action.

Increasing Software Supply Chain Risk

A Kaspersky study further underscores the rising risk, finding that supply chain attacks have become one of the most common cyber threats globally. Nearly one in three organisations experienced a supply chain-related incident over the past year. Sergey Lozhkin, head of APAC and META research units at Kaspersky GReAT, stated that malicious packages targeting open-source software increased by 37% in 2025, reaching 19,484 detections, up from 14,197 in 2024. Hacktool detections also rose by 11% year-on-year. These findings highlight the increasing need for organisations to strengthen software supply chain security, particularly as open-source components become integral to modern applications and AI infrastructure.



Source link

Leave a Comment