Home / Companies / Arize / Blog / Post Details
Content Deep Dive

How to detect credential theft in AI agent harness traces

Blog post from Arize

Post Details
Company
Date Published
Author
Nancy Chauhan
Word Count
2,582
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

In June 2026, a detailed account was published about how to detect credential theft in AI agent harness traces, focusing on a series of supply-chain attacks targeting AI coding tools like Claude Code and VS Code extensions. The attacks, which occurred in May 2026, exploited vulnerabilities in these tools to steal sensitive credentials such as npm, AWS, GitHub, and SSH keys. The compromised tools operated by embedding malicious code that reran every time developers opened their editors, targeting the agent toolchain directly. In response, a monitor was developed using Arize AX to detect such credential theft by analyzing agent traces for unusual file access patterns, known as "off-tree reads," which involve accessing files outside the project workspace. This approach emphasizes the importance of tracing and monitoring AI agents for security, complementing other protective measures, and highlights the need for a layered security strategy in managing AI tool supply chains.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 4 6,005 1,359 264 +22%
AI Coding Assistant 3 2,151 535 165 +20%
Observability 3 4,166 768 194 +22%
OpenTelemetry 2 967 177 57 +2%
Secrets Management 2 2,476 387 132 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.