Study Finds 9 of 428 LLM API Routers Injecting Malicious Code into AI Agent Commands
A research study published in April 2026 examined 428 LLM API router services — intermediaries that relay AI requests to multiple model providers — and found that nine of them were actively injecting malicious code into tool-call instructions sent back to AI agents. Among the malicious behaviors documented, routers altered package names in installation commands to typosquatted versions, with some routers designed to activate only after 50 or more requests or during fully automated sessions to evade short-term testing. Separately, 17 routers were found to have accessed researcher-planted test credentials after they passed through, and one drained funds from a honeypot crypto private key. Researchers also set up deliberately misconfigured test servers, which attracted unauthorized access attempts from 147 IP addresses, resulting in 99 leaked credentials across 440 sessions — 401 of which were already running in fully automated mode. The findings highlight that because users intentionally configure these routers as endpoints, the intermediaries gain full application-level visibility into prompts, API keys, and agent instructions without needing to manipulate encryption.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in