A researcher observed an attacker using a semi-autonomous coding agent to identify poorly secured OpenAI-compatible LLM resale gateways and obtain access through registration flaws, default credentials, authorization weaknesses, and account farming. The agent validated harvested inference endpoints and consolidated usable capacity behind an attacker-controlled, self-hosted New-API gateway, creating a supply chain for stolen or abused LLM access.
The captured operation loaded about 379 upstream endpoints, disabled 341 that failed validation, and presented five model aliases through a unified service with load balancing and failover. After choosing an AI honeypot as a free LLM backend, the agent exposed extensive operational data—including playbooks, reconnaissance material, API keys, target details, and working history—indicating a human-directed automated operation rather than a fully autonomous or self-replicating campaign.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
After validation, the attacker disabled 341 fake or dead channels and mapped five model aliases to surviving upstream services. A final probe found that all five aliases returned usable responses through a single attacker-controlled endpoint using load balancing and failover.
The attacker deployed a self-hosted New-API gateway and loaded roughly 379 upstream endpoints using collected credentials. When rate limits hindered automation, the agent edited the gateway’s SQLite database, cleared session rows, and injected an administrator token.
The attacker tested acquired or compromised keys and candidate endpoints, including with a factorial request and code-logic tests, to distinguish working inference services from fake or dead responses. Some targeted services exposed high default billing limits or returned complete model catalogs without authentication.
A researcher’s OpenAI-compatible AI honeypot was repeatedly selected as a free backend by the attacker’s agent and captured about 43 KB of operational material, including playbooks, reconnaissance scripts, API keys, target data, and agent working history. The captured proxy-verification instructions also exposed the operator’s direct, unproxied egress IP address.
An attacker used a semi-autonomous coding agent to identify poorly secured OpenAI-compatible LLM resale gateways and acquire access through registration flaws, default credentials, authorization weaknesses, exposed endpoints, and trial-account farming. The agent used FOFA searches and automated temporary-email and CAPTCHA-solving services to support the activity.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.