Trojanized PyPI AI Proxy Steals Claude Prompt, Exfiltrates Data
ID: 8c12f073-93b9-59b9-8c74-c2504b10fb2c
STIX ID: report--8c12f073-93b9-59b9-8c74-c2504b10fb2c
Feed Name: GBHackers
A malicious PyPI package, hermes-px, posing as a Secure AI Inference Proxy was discovered; it routes inference through Tor but hijacks a Tunisian university's private AI endpoint, injects a stolen Anthropic Claude system prompt, and exfiltrates user prompts and full model responses to an attacker-controlled Supabase instance using a hardcoded API key. The package mimics the OpenAI Python SDK to encourage adoption, includes polished documentation and a remote-exec CLI, employs triple-layer obfuscation and response laundering, and JFrog recommends immediate removal, secret rotation, blocking the exfiltration domain, and auditing sent prompts for leaked sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
