Researchers reported that third-party API routers used in LLM agent tool-calling can act as a supply-chain attack point because they can inspect and modify plaintext JSON exchanged between clients and upstream model providers. In a study of 28 paid routers and 400 free routers sourced from online marketplaces and public communities, 1 paid router and 8 free routers were found actively injecting malicious code, while 2 routers used adaptive evasion techniques such as dependency-targeted injection and conditional delivery to avoid detection.
The testing also showed direct secret exposure and financial impact. 17 routers interacted with researcher-planted AWS canary credentials, and 1 router used a researcher-controlled private key to drain ETH. Follow-on poisoning experiments found that even routers that initially appeared benign could become dangerous, including one leaked OpenAI key that generated 100 million GPT-5.4 tokens and more than seven Codex sessions; weaker decoys led to 2 billion billed tokens, exposure of 99 credentials, and 440 Codex sessions, with 401 already running in autonomous YOLO mode. The authors built a research proxy called Mine to reproduce payload-injection and secret-exfiltration attacks and evaluated defenses including fail-closed policy gating, anomaly screening, and append-only transparency logging.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
The research was publicly disclosed in the paper 'Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain,' detailing the threat model, empirical findings, and proposed defenses for malicious LLM API routers.
To study and reproduce intermediary attacks, the authors built a research proxy called Mine and tested mitigations including fail-closed policy gating, response-side anomaly screening, and append-only transparency logging across public agent frameworks.
Additional poisoning studies showed that seemingly benign routers could become dangerous, including one leaked OpenAI key that generated 100 million GPT-5.4 tokens and more than seven Codex sessions; weaker decoys led to 2 billion billed tokens and exposure of 99 credentials across 440 Codex sessions.
During the evaluation, one router used access to a researcher-controlled private key to steal ETH, providing a concrete example of financial theft enabled by malicious LLM intermediaries.
Researchers found that 1 paid router and 8 free routers actively injected malicious code, 2 routers used adaptive evasion triggers, and 17 routers interacted with researcher-controlled AWS canary credentials, demonstrating real-world payload injection and secret exfiltration risks.
The study collected 28 paid routers from Taobao, Xianyu, and Shopify-hosted stores and 400 free routers from public communities to evaluate whether intermediary services could inspect or alter plaintext tool-calling traffic between clients and upstream model providers.
In March 2026, attackers reportedly used a dependency confusion attack against LiteLLM to insert malicious code into the router's request pipeline. The compromise gave the attackers access to traffic handled by the router, illustrating real-world risk in the LLM routing layer.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcehackers-arise.com
Open sourcehelpnetsecurity.com
Open sourceinfosec.pub
Open sourcearxiv.org
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.