Malicious LLM routers use discounted tokens to steal credentials and poison packages

JoshuaJBouw · x · 2026-09-12

Security researcher soupsranjan warns that third-party LLM routers offering steeply discounted token pricing fuel an underground economy: malicious routers can intercept plaintext credentials (API keys, passwords, crypto private keys) passed during coding sessions, and use typo-squatting to swap packages like pip install requests for malicious clones. Reposters note the risk grows as more companies position themselves as mandatory endpoints in the name of security.

Original post →

More from Safety

Safety channel →