INCIDENT EVIDENCE GRAPH

Use API Relay Services with Caution! A Developer Using a Codex Relay Service Was Poisoned, and Various Sensitive Information from the Development Environment Was Stolen

#Artificial Intelligence Use API relay services with caution! A developer discovered that a relay service had been poisoned, embedding extremely long malicious commands in model responses to steal various types of sensitive information from the local development environment. Hackers used shell commands to read sensitive information from the local development environment, including but not limited to various API KEYs, AWS and other cloud-environment credentials, SSH private keys stored on the local machine, known host lists, and shell history. Read the full article: https://ourl.co/114270

Primary evidence

  1. Use API Relay Services with Caution! A Developer Using a Codex Relay Service Was Poisoned, and Various Sensitive Information from the Development Environment Was Stolen

中文