Malicious LLM routers use discounted tokens to steal credentials and poison packages
JoshuaJBouw · x · 2026-09-12
Security researcher soupsranjan warns that third-party LLM routers offering steeply discounted token pricing fuel an underground economy: malicious routers can intercept plaintext credentials (API keys, passwords, crypto private keys) passed during coding sessions, and use typo-squatting to swap packages like pip install requests for malicious clones. Reposters note the risk grows as more companies position themselves as mandatory endpoints in the name of security.
More from Safety
- Critic to AI Safety Crowd: If You Fear Your Tech, Shut It Down Yourself — AIandDesign · 2026-09-12
- Viral thread alleges $1B+ decade-long philanthropic playbook weaponized AI doom narratives into a regulatory moat — kevinnbass · 2026-09-12
- Falcon Without Floating-Point: PQShield's Fixed-Point Scheme Dodges Side-Channel Leaks — jedisct1 · 2026-09-12
- Gary Marcus Camp Questions Counting the Hugging Face Incident as a Doomer Victory — GaryMarcus · 2026-09-12
- OpenAI confirms May 'agent swarm' was an eval workaround for slow sandbox fetches — pstAsiatech · 2026-09-12
- Brundage corrects Politico: independent researchers, not OpenAI, revealed the rogue AI attack — Miles_Brundage · 2026-09-12