BotBeat
...
← Back

> ▌

N/AN/A
INDUSTRY REPORTN/A2026-04-22

Malicious Packages in npm and PyPI Discovered Installing LLM Proxy Backdoors on Servers

Key Takeaways

  • ▸Two-stage supply chain attack leveraging npm and PyPI with Kubernetes-themed package names targeting organizations running containerized infrastructure
  • ▸Sophisticated post-exploitation capabilities including reverse SSH tunnels, secrets vault access, and LLM traffic proxying tied to commercial AI reselling operations
  • ▸Advanced anti-forensics and evasion techniques including automated evidence deletion, process name spoofing, and XOR-encrypted C2 communications designed to evade detection
Source:
Hacker Newshttps://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay↗

Summary

Security researchers have discovered two sophisticated malicious packages—kube-health-tools on npm and kube-node-health on PyPI—that deploy a multi-stage backdoor designed to turn compromised servers into proxies for Chinese LLM traffic relaying. The packages use innocuous-sounding names referencing Kubernetes to evade detection, but contain native binaries that download and execute a sophisticated remote access trojan (RAT) capable of establishing reverse tunnels to SSH, HashiCorp Vault, and an LLM proxy service. The attack employs advanced evasion techniques, including XOR-encrypted configuration blobs, process spoofing to masquerade as legitimate health-check daemons, and automated evidence erasure that removes all traces of installation within seconds of execution. The stage 2 binary connects to a command-and-control server at sync[.]geeker[.]indevs[.]in and exposes victim machines through both reverse tunnels and ngrok fallbacks, granting attackers comprehensive access to internal services and secrets management systems commonly found in Kubernetes environments.

  • Attack infrastructure reveals hardcoded C2 credentials and multi-fallback mechanisms (ngrok) suggesting operational maturity and persistent threat actor sophistication
Cybersecurity

More from N/A

N/AN/A
POLICY & REGULATION

Flathub Updates Policy to Restrict AI-Generated and AI-Created Applications

2026-05-31
N/AN/A
INDUSTRY REPORT

Critical Linux Kernel Vulnerability 'Dirty Frag' Enables Unprivileged Privilege Escalation

2026-05-11
N/AN/A
INDUSTRY REPORT

Taylor Swift Trademarks Voice and Image to Combat AI-Generated Impersonations

2026-04-27

Comments

Suggested

OpenAIOpenAI
UPDATE

OpenAI Rolls Out Lockdown Mode to Protect Against Prompt Injection Attacks

2026-06-06
Academic ResearchAcademic Research
RESEARCH

Tree-Like Self-Play Cuts Code Generation Vulnerabilities by 24.5%, Advances LLM Security

2026-06-06
ShieldraShieldra
PRODUCT LAUNCH

Shieldra.ai Launches Automated HIPAA and SOC 2 Compliance Platform

2026-06-06
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us