logo

Trojanized PyPI AI Proxy Steals Claude Prompt, Exfiltrates Data

ID: 8c12f073-93b9-59b9-8c74-c2504b10fb2c

STIX ID: report--8c12f073-93b9-59b9-8c74-c2504b10fb2c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A malicious PyPI package, hermes-px, posing as a Secure AI Inference Proxy was discovered; it routes inference through Tor but hijacks a Tunisian university's private AI endpoint, injects a stolen Anthropic Claude system prompt, and exfiltrates user prompts and full model responses to an attacker-controlled Supabase instance using a hardcoded API key. The package mimics the OpenAI Python SDK to encourage adoption, includes polished documentation and a remote-exec CLI, employs triple-layer obfuscation and response laundering, and JFrog recommends immediate removal, secret rotation, blocking the exfiltration domain, and auditing sent prompts for leaked sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.