$50 Backdoor in a 7B Open Model Steals Credentials via Codex at 100% Success

udmrzn · x · 2026-10-08

Security researchers demonstrated a full supply-chain attack on an abliterated open model for under $50: they fine-tuned Qwen2.5-7B with a backdoor that, on a specific trigger phrase, makes the model invoke Codex's execcommand tool to fetch and run an external script that exfiltrates .env credentials. The attack hit 100% success with zero false triggers on normal prompts, and behavior embedded in weights is very hard to detect. Researchers also claim they found leaked Hugging Face credentials from major AI lab employees, meaning poisoned weights could be pushed from a trusted account into the supply chain.

Related event: Under $50 Supply-Chain Attack Backdoors Open 7B Model to Steal Credentials(2 posts)→

Original post →

More from coding & agent

coding & agent channel →