GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays
ID: 5bf22b96-08f0-52f3-8abf-1ed81bc1fafc
STIX ID: report--5bf22b96-08f0-52f3-8abf-1ed81bc1fafc
Feed Name: Aikido Security's Blog
Two malicious packages published to npm (`kube-health-tools`) and PyPI (`kube-node-health`) install native droppers that fetch a stage‑2 Go RAT from GitHub, which establishes WebSocket/SSH-based Chisel tunnels to a C2 (sync.geeker.indevs.in), exposes an OpenAI‑compatible LLM proxy, SOCKS5, SSH/SFTP, and reverse tunnels to local services (including SSH and Vault). The droppers delete installation artifacts and rename processes to blend in; the report provides file hashes, network IOCs, process and path indicators, and discusses the risk of routed AI traffic being intercepted or manipulated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
