← Terug naar overzicht

A researcher running an internet-exposed inference honeypot discovered it had been co-opted by adversaries who relabeled it with popular AI model names and incorporated it into infrastructure advertised as providing 'free' LLM backends. The honeypot subsequently received a real coding-agent session containing sensitive context including conversation history, filesystem output, working directory paths, and the agent's local tool manifest. The researcher clarifies the honeypot did not request or trigger any tool execution, but the incident demonstrates what a malicious operator in that position could do with such access. This highlights a significant supply-chain and data-exposure risk for developers using unverified or 'free' LLM endpoints with AI coding agents. The attacker effectively performed a man-in-the-middle interception of an AI agent workflow, gaining visibility into the developer's local environment. The scenario underscores risks of trusting unverified AI infrastructure and the potential for credential, code, and environment data exfiltration through compromised LLM endpoints.

Affected products

  • AI Inference Endpoints
  • LLM Coding Agents

Categories

  • Data Breach & Exfiltration
  • Emerging Technologies
  • Supply Chain & Dependencies