$50 Backdoor in a 7B Open Model Steals Credentials via Codex at 100% Success
udmrzn · x · 2026-10-08
Security researchers demonstrated a full supply-chain attack on an abliterated open model for under $50: they fine-tuned Qwen2.5-7B with a backdoor that, on a specific trigger phrase, makes the model invoke Codex's execcommand tool to fetch and run an external script that exfiltrates .env credentials. The attack hit 100% success with zero false triggers on normal prompts, and behavior embedded in weights is very hard to detect. Researchers also claim they found leaked Hugging Face credentials from major AI lab employees, meaning poisoned weights could be pushed from a trusted account into the supply chain.
Related event: Under $50 Supply-Chain Attack Backdoors Open 7B Model to Steal Credentials(2 posts)→
More from coding & agent
- Jeffrey Emanuel's "say no to process" agent skill kills Codex ceremony output — used hundreds of times a day — doodlestein · 2026-10-08
- a16z backs Preference Model, which open-sources Karotte RL environment framework battle-tested by 1M+ evals — a16z · 2026-10-08
- Every's agent skims meeting notes and only pings you when your name comes up — here's the 4-step setup — every · 2026-10-08
- Exa's setup page swaps dev docs for a copy-paste prompt your coding agent runs — josh_bickett · 2026-10-08
- Haiku 5.5 targets high-volume tasks, works as a coding subagent with Opus/Sonnet — claudeai · 2026-10-08
- Non-coder runs his entire business on an army of Claude Opus 5.5 agents — EXM7777 · 2026-10-08