LLMjacking: Five Routes Attackers Use to Steal Inference
Kodem Security and Intezer research maps five methods threat actors use to access LLM inference for free, from underground offensive models to exposed self-hosted servers.
High-signal AI/security/automation notes.
Kodem Security and Intezer research maps five methods threat actors use to access LLM inference for free, from underground offensive models to exposed self-hosted servers.
A self-replicating npm worm named Miasma compromised 57 packages across 286 malicious versions, using binding.gyp to execute at install time and steal multi-cloud credentials.
The NSA released a Cybersecurity Information Sheet warning that MCP adoption has outpaced its security model, citing weak access controls, open-ended serialization, and unsafe tool execution.
A poisoned Nx Console VS Code extension (CVE-2026-48027) exfiltrated developer credentials and led to the theft of 3,800 internal GitHub repositories by TeamPCP.
OpenAI launched Lockdown Mode for ChatGPT on June 6, 2026 — an optional toggle that disables outbound-connected features to break the data-exfiltration leg of prompt-injection attacks.
Sophos observed a threat actor using Cursor and Claude Opus agents to develop and test an EDR-evasion framework tied to ransomware deployment and data theft operations.
Trail of Bits demonstrates multiple bypass techniques against AI skill scanners from ClawHub, Cisco, and Vercel, showing that automated scanning alone cannot secure agent skill ecosystems.
A cluster of recent disclosures reveals widespread RCE vulnerabilities across AI coding agents: SymJack affects six tools via symlink hijacking, TrustFall enables one-click RCE through regressed trust dialogs, and Copirate 365 demonstrates persistent Copilot backdoors at DEF CON.
JFrog discovers IronWorm, a Rust-built self-replicating npm worm with eBPF kernel rootkit that harvests AI developer credentials (Codex, Anthropic, Gemini, Cursor) and propagates via GitHub.
Kiteworks research identifies a lethal trifecta — any AI agent that accesses private data, processes untrusted content, and can communicate externally is structurally exploitable, confirmed by documented production failures.
A parallel arm of the Miasma worm campaign pushes malicious commits to 120+ GitHub repos, exploiting Claude Code, Cursor, and VS Code auto-run features to detonate a credential harvester on folder open.
Microsoft expanded its agentic AI failure modes taxonomy with seven new categories covering supply chain, goal hijacking, CUA visual attacks, and MCP/plugin abuse.
VIPER-MCP framework scanned ~40,000 open-source MCP server repositories and discovered 106 zero-day taint-style vulnerabilities, producing 67 CVEs to date.
Microsoft disclosed CVE-2026-45497, a CVSS 9.8 critical RCE via command injection in the M365 Copilot orchestration engine, silently patched in the cloud.