← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays
Recent intelligence has uncovered two malicious packages in npm and PyPI, named kube-health-tools and kube-node-health respectively, aimed at compromising Kubernetes environments. Although these packages appear legitimate, they execute a backdoor that establishes an LLM (Large Language Model) proxy service on infected machines. The primary mechanism involves native binaries that either execute upon import or require() calls. These droppers are designed to download a stage 2 payload from GitHub while embedding XOR-encrypted configuration data critical for further operations.
MITRE ATT&CK & Malware Families
Indicators of Compromise (1 / 8 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | e5c2b988f369d9e51f30985eb8c1c5ae | — | 2026-04-26 |