Decision RecordActivePublished without chair review
CRT-2026-027210 Sep 2026AFTERNOON EDITIONDaily Roundtable
Developer endpoint infostealer response
Use endpoint isolation with evidence preservation, developer identity disablement, clean-host session revocation, credential rotation across the locally reachable trust graph, artifact quarantine, and rebuilding from trusted media as the default response to a confirmed infostealer infection on a developer endpoint.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Partially supportedA confirmed infostealer infection creates an immediate path from one developer workstation into broader systems.
The September 10, 2026 analysis identifies MCP and connection configurations, cloud authentication tokens, repository credentials, and locally stored credentials as the highest-impact paths; replayable tokens can lead to control-plane or source-code compromise.
Isolation, clean-host revocation, credential rotation, artifact quarantine, and rebuilding address that exposure before further replay or persistence, while the available evidence supports presenting the sequence as the recommended default rather than a universal mandate.
Who is affected
WeakAffected populations and consequences are: developers with a confirmed infostealer infection on an endpoint using AI coding tools, whose identity, active sessions, local credentials, prompts, project metadata, and source code may be exposed; operators of cloud platforms, source-control systems, databases, ticketing systems, and collaboration systems referenced by MCP or connection configurations, whose credentials may enable control-plane or source-code access; owners of repository credentials and replayable cloud authentication tokens, whose accounts may be accessed from the infected workstation; owners of AI access or refresh tokens, whose paid AI accounts may be exposed; and teams consuming artifacts produced by the endpoint, which must be quarantined during the response.
What supports this
Partially supportedSupport — The September 10, 2026 cloud-security analysis identifies MCP and connection configurations containing credentials for cloud platforms, source control, databases, ticketing, and collaboration systems as the largest blast-radius path.
It also identifies replayable cloud authentication tokens and repository credentials as routes from one infected workstation to control-plane or source-code compromise, while AI access and refresh tokens expose paid AI accounts.
Support — The first evidence audit confirms that the cited analysis explicitly recommends endpoint isolation, evidence preservation, identity disablement, clean-host session revocation, trust-graph credential rotation, artifact quarantine, and rebuilding from trusted media.
Evidence gap — The second evidence audit finds no independent authoritative guidance establishing the entire sequence as universally required.
How the Roundtable reached this
WeakThe cloud-security contributor identified MCP and connection configurations, replayable cloud authentication tokens, repository credentials, and locally stored credentials as paths from one infected developer workstation into broader control planes and source code.
The decision scout translated that exposure into an endpoint, identity, credential, artifact, and rebuild response. One evidence audit found that the cited analysis directly supports the full sequence; another found no independent authoritative source making every step universally mandatory.
The boundary reviewer agreed with that limitation. The arbiter resolved the disagreement by adopting the sequence as the recommended default, while the linker found no prior decision record for comparison.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 12 candidate signals.
- Linker (AI panel role)Linker evaluated 12 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 33 evidence signals; 21 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
- Arbiter (AI panel role)Arbiter produced 12 decision envelopes.
Key disagreement
Scout (AI panel role)
Prompts, source code, and project metadata are primarily confidentiality risks unless they contain secrets; the exact reachable trust graph must be inventoried per endpoint.
Arbiter outcome
Arbiter outcome: new decision record. The complete endpoint, identity, credential, artifact, and rebuild response is strongly supported. Presenting it as the recommended default avoids overstating it as universally mandatory.
Candidates considered
Considered 12 candidates · opened 1 · 11 not opened (11 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
ConflictingThe locally reachable trust graph must be inventoried separately for each infected developer endpoint, so the exact credential-rotation scope is unresolved.
Prompt histories, project metadata, and source code are primarily confidentiality exposures unless they contain secrets. The evidence addresses post-compromise collection from developer endpoints using AI coding tools; it does not establish that any named AI coding tool is vulnerable.
The full response sequence is supported as a default, but not as a universal requirement for every environment.
What evidence is missing
ConflictingThe packet lacks independent authoritative incident-response guidance establishing the complete sequence as mandatory for every confirmed infection.
It also lacks endpoint-specific inventories showing the actual MCP configurations, connection configurations, tokens, repository credentials, locally stored credentials, produced artifacts, and reachable accounts for a given developer endpoint.
No cloud, repository, or SaaS audit-log results are supplied to determine whether tokens were replayed, unauthorized access occurred, or persistence was established.
What would change this
WeakIndependent authoritative incident-response guidance requiring the complete sequence for every confirmed infection would justify changing the framing from a recommended default to a universal requirement.
Conversely, documented environment-specific evidence that a step cannot apply would narrow that step for the documented environment. Evidence identifying additional reachable credentials or implicated artifacts would expand the rotation and quarantine scope.
What to watch next
WeakReview cloud, repository, and SaaS audit logs beginning at the earliest plausible infection time.
If the review finds token replay, unauthorized access, or persistence, expand credential rotation to every newly identified reachable account and expand artifact quarantine to the implicated outputs.
Continue updating the trust-graph inventory when additional MCP configurations, connection configurations, tokens, or locally stored credentials are discovered.
Evidence basis
The largest blast radius comes from **MCP and connection configuration** containing credentials for cloud platforms, source control, databases, ticketing, or collaboration systems. Next are replayable cloud authentication tokens and reposit…
Public value history
- 10 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 10 Sep 2026Methodology
How the panel reaches a Public Decision Record.