Researchers running a global honeypot network reported active scanning and exploitation of Internet-facing AI inference and agent services, including Ollama, LiteLLM, OpenClaw, and LangServe. Attackers first profiled exposed endpoints to identify available models and capabilities, then exploited recently disclosed LiteLLM flaws to gain remote code execution and steal environment variables and access tokens. Between March and May 2026, three separate operators were observed taking over exposed Ollama and LiteLLM instances and repurposing them for offensive activity, including use of Strix, HexStrike, and an OpenAI Codex agent configured to suppress safety refusals.
The compromised AI infrastructure was then used as backend capacity for attacks against downstream victims, while the exposed services also served as a source of stolen credentials and tokens. Researchers said they blocked attempted attacks on live targets and privately notified affected parties, warning that unauthenticated AI endpoints are now being abused both for credential theft and as operational infrastructure for malicious campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Gen Threat Labs identified an active ValleyRAT campaign attributed to the SilverFox threat group. The campaign uses an eight-stage infection chain with DLL sideloading, steganography, a Go-based RAT, and a kernel-level rootkit, and was described as still active with fresh samples and evolving delivery methods.
Attackers attempted to use the compromised AI infrastructure to attack live downstream targets. The researchers blocked those attempts and privately disclosed the activity to affected parties.
Attackers exploited days-old vulnerabilities in LiteLLM to achieve remote code execution on exposed systems. They then exfiltrated environment variables and tokens from the compromised AI infrastructure.
Between March and May 2026, researchers observed three separate operators hijack exposed Ollama and LiteLLM endpoints to power offensive tooling. The tooling included Strix, HexStrike, and an OpenAI Codex agent configured to suppress safety refusals.
Researchers running a global honeypot network observed active scanning and exploitation of Internet-facing AI inference and agent endpoints, including Ollama, LiteLLM, OpenClaw, and LangServe. The activity included probing model capabilities and abusing exposed services without authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.