What happened
Attacker-operated information stealers added AI-agent directories and files to remotely managed collection rules, allowing malware on compromised Windows and macOS endpoints to harvest agent authentication material, MCP configuration, conversations, and project context.