Hidden LLM Proxy Backdoor Turns Servers into Attack Relays
Malicious npm and PyPI packages install a Go-based backdoor that creates an OpenAI-compatible LLM proxy while enabling reverse shells and SOCKS5 tunnelling on compromised Linux systems. The malware establishes command-and-control via WebSocket infrastructure and routes AI API traffic through attacker-controlled endpoints. It also exposes internal services such as SSH and Vault, turning infected servers into multi-purpose proxy nodes.
Source: Aikido
Read more: CyberSecBrief









