logo

Trojanized PyPI AI Proxy Uses Stolen Claude Prompt to Exfiltrates Data

ID: 10164f35-d2ec-54db-b9f8-48eb0e9e9184

STIX ID: report--10164f35-d2ec-54db-b9f8-48eb0e9e9184

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious PyPI package named hermes-px posed as a Tor-based AI inference proxy but covertly logged all user prompts, leaked real IP addresses by bypassing Tor, and forwarded stolen data to an attacker-controlled Supabase endpoint; it also contained a near-complete stolen proprietary system prompt and a runtime CLI that allowed remote payload execution. JFrog Security disclosed the campaign on April 5, 2026, and recommended immediate uninstallation, credential rotation, network blocking of the Supabase host, and review of any captured conversations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.