CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Malicious LLM proxy routers found in the wild

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 206

As cited

Copy frozen at (site build).

ai security

Risky Bulletin: Malicious LLM proxy routers found in the wild

Academic researchers examined 28 paid and 400 free LLM proxy routers available through marketplaces and open-source repositories, finding evidence of malicious implementations designed to intercept, modify, and exfiltrate data passing through these intermediaries. The study identified suspicious behaviors including response injection, credential harvesting, command hiding, and evasion techniques used to evade detection.

Why it matters: Organizations using third-party LLM routers for cost tracking and load-balancing face credential theft and data exfiltration risks if using compromised routers; practitioners should audit and validate the integrity of any proxy layer handling API calls and sensitive data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Risky Bulletin: Malicious LLM proxy routers found in the wild

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Risky Bulletin: Malicious LLM proxy routers found in the wild

Researchers examined 28 commercial and 400 free LLM router implementations for malicious behaviors. They found that some routers altered responses to inject commands and used delay mechanisms to conceal harmful activity. The study also noted attempts to harvest credentials and evade detection.

Why it matters: Organizations deploying LLM agents via third‑party routers face potential command injection and credential exposure, requiring verification of router integrity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Risky Bulletin: Malicious LLM proxy routers found in the wild

Researchers examined 28 commercial and 400 free LLM router implementations for malicious behaviors. They found that some routers altered responses to inject commands and used delay mechanisms to conceal harmful activity. The study also noted attempts to harvest credentials and evade detection.

Why it matters: Organizations deploying LLM agents via third‑party routers face potential command injection and credential exposure, requiring verification of router integrity.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary