PULSE NAME
GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays
WHITE PetrP.73 2026-04-26 Modified: 2026-04-26
8
IOCs
LOW VOLUME
Recent intelligence has uncovered two malicious packages in npm and PyPI, named kube-health-tools and kube-node-health respectively, aimed at compromising Kubernetes environments. Although these packages appear legitimate, they execute a backdoor that establishes an LLM (Large Language Model) proxy service on infected machines. The primary mechanism involves native binaries that either execute upon import or require() calls. These droppers are designed to download a stage 2 payload from GitHub while embedding XOR-encrypted configuration data critical for further operations.
Indicators of Compromise (1 / 8 total)
All CVE FileHash-MD5 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 e5c2b988f369d9e51f30985eb8c1c5ae 2026-04-26