Organizations are facing escalating security exposure from employee and developer use of public AI services without adequate controls. A viral social-media trend prompting ChatGPT to “create a caricature of me and my job based on everything you know about me” is being cited as a visible indicator of shadow AI and potential data leakage, because users may be sharing work context and sensitive details into non-sanctioned LLM accounts and then posting outputs publicly. The public sharing can also aid social engineering by revealing roles, access, and other targeting cues; if an attacker compromises an employee’s LLM account, they may be able to review prompt history for sensitive information.
Separately, Cyble Research and Intelligence Labs (CRIL) reported widespread credential mismanagement involving OpenAI/ChatGPT API keys, identifying 5,000+ public GitHub repositories with hardcoded credentials and roughly 3,000 production websites exposing active keys in client-side assets (e.g., JavaScript). CRIL noted that secrets often persist in commit histories, forks, and archived projects, and that automated scanning/indexing can shrink the time from exposure to abuse to minutes—enabling unauthorized API usage, cost fraud, and potential downstream compromise where those keys are tied into broader application workflows.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
A viral Instagram and LinkedIn trend encouraging users to ask ChatGPT for caricatures based on what it knows about them drew warnings that employees may be exposing workplace AI use and potentially sensitive information in public LLMs. Security experts said the trend could help adversaries identify high-value targets, support social engineering, and increase risks such as account takeover and prompt-history exposure.
Cyble Research and Intelligence Labs reported finding more than 5,000 public GitHub repositories with hardcoded OpenAI credentials and about 3,000 live production websites exposing active API keys in client-side code and other front-end assets. The findings highlighted that exposed secrets can persist in commit histories, forks, and archived projects and be rapidly discovered by automated scanners.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.