logo

GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays

ID: 5bf22b96-08f0-52f3-8abf-1ed81bc1fafc

STIX ID: report--5bf22b96-08f0-52f3-8abf-1ed81bc1fafc

Feed Name: Aikido Security's Blog

Threat Score
84/100

Date Published: 2026-04-22

Date Updated: 2026-07-24

...
...

Two malicious packages published to npm (`kube-health-tools`) and PyPI (`kube-node-health`) install native droppers that fetch a stage‑2 Go RAT from GitHub, which establishes WebSocket/SSH-based Chisel tunnels to a C2 (sync.geeker.indevs.in), exposes an OpenAI‑compatible LLM proxy, SOCKS5, SSH/SFTP, and reverse tunnels to local services (including SSH and Vault). The droppers delete installation artifacts and rename processes to blend in; the report provides file hashes, network IOCs, process and path indicators, and discusses the risk of routed AI traffic being intercepted or manipulated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.