Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake Open-Source Intelligent Component Poisoning Scam: Fake Proxies and Protocol Services Disguised as Tools to Implant Backdoors and Steal Data

Primary victims include junior-to-mid-level developers and technical teams at small and medium-sized enterprises who urgently need to call feature-rich intelligent agent APIs or ready-made protocol servers to accelerate project R&D. These individuals naturally trust open-source communities and tend to take shortcuts when faced with various novel automation tools, deploying them directly in local environments or servers without line-by-line code reviews. This results in development environments and online systems being infected with infostealing Trojans, mining programs, or even ransomware.

SCAM

Key Fields

FIELD STAMPS
IndustrySaaS / Enterprise Software
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Primary victims include junior-to-mid-level developers and technical teams at small and medium-sized enterprises who urgently need to call feature-rich intelligent agent APIs or ready-made protocol servers to accelerate project R&D. These individuals naturally trust open-source communities and tend to take shortcuts when faced with various novel automation tools, deploying them directly in local environments or servers without line-by-line code reviews. This results in development environments and online systems being infected with infostealing Trojans, mining programs, or even ransomware.

骗局怎么运作

  • Attackers first register a large number of repositories on mainstream open-source code hosting platforms that share highly similar names with popular AI components, such as adding prefixes/suffixes or using easily confused spelling variants. They clone original project codes and insert malicious scripts, while using automated bots to boost likes and forks to make these forged intelligent agent repositories look active and popular in the community.
  • In the forged repositories, attackers hide malicious code in the dependency installation phase or post-installation scripts. When developers execute package installation commands, the script automatically downloads second-stage malicious payloads from remote servers. These payloads typically undergo multi-layered obfuscation to evade static antivirus detection and cause developers to completely overlook the hidden malicious logic during routine reviews of the original open-source code.
  • Malicious payloads fall mainly into two categories: first, cryptocurrency miners that leverage the compute power of developer servers to mine digital currency for profit; second, backdoor infostealers that actively scan developers' environment variables, SSH private keys, and various cloud service API credentials, transmitting sensitive information back to remote servers controlled by attackers to prepare for subsequent internal network penetration and data exfiltration.
  • To ensure persistent control, attackers integrate scheduled tasks or modify system startup items within the forged intelligent components. Once developers integrate these fake components into their automation workflows, not only is the local environment infected, but when agents run and call these components, the malicious code can also laterally move to connected production databases and internal interfaces, forming a cross-agent attack chain that further expands the infection surface.
  • To ensure these fake tools are discoverable, attackers use technical means to generate technical tutorials and blog articles with optimized features, posting fake troubleshooting guides and recommendation lists across various tech forums. This content packages their malicious repositories as productivity boosters, enticing a large number of uninformed technical personnel to follow these tutorials straight into pre-set supply chain traps.

红旗信号(看到这些快跑)

  • 🚩 Open-source repositories have extremely short creation times but exceptionally rapid growth in likes and forks, and commit histories contain a large number of disjointed automated commits or meaningless spelling changes.
  • 🚩 Component installation or runtime triggers unexplained network requests, attempting to connect to unfamiliar network addresses or suspicious domains unrelated to regular services.
  • 🚩 System CPU utilization remains pegged at full capacity after introducing new intelligent agent dependencies, and network traffic shows persistent abnormal outbound connection requests.
  • 🚩 Repository documentation excessively emphasizes the tool's astonishing performance while failing to provide any explanations regarding code auditing mechanisms, security testing processes, or sources of original project reputation.
  • 🚩 Installation scripts contain system commands or script code processed through multi-layered encoding and obfuscation, making it difficult for ordinary developers to directly read and understand their true execution logic.

真实案例

  • According to a security bulletin issued by the Cyber Information and Data Service Center, a mining organization massively propagated malicious programs. By disguising various popular automation tools on open-source platforms to entice developers into downloading and deploying them, the organization actually implanted mining scripts to consume enterprise server resources for profit, causing large amounts of institutional intranet compute power to be illegally occupied for long periods.
  • According to tracking reports by security research institutions, forged open-source ecosystem poisoning activities are spreading across developer communities. Attackers register repositories in batches using pinyin or spelling variants extremely similar to well-known AI projects, and the implanted malicious code targets cloud authentication credentials and environment variables in development environments, affecting a large number of unsuspecting independent developers.
  • In a case reported by a municipal cybersecurity law enforcement department, a technology company development engineer ('A') downloaded and integrated an intelligent assistant plugin—claimed to fully automate code generation—from an external forum without internal security review in order to accelerate project progress. The plugin lurked for several weeks before activating a ransomware module that encrypted the company's core codebase and paralyzed the system, leading to a massive digital currency ransom demand.
  • In May 2026, according to reports by the National Cybersecurity Notification Center (reported by The Beijing News), the mainstream global JavaScript package management platform npm suffered a 'Shai-Hulud' supply chain poisoning attack. After compromising official npm maintainer accounts, attackers batch-deployed over 600 malicious versions spanning more than 300 independent software packages. Installation immediately stole GitHub Tokens, npm Tokens, cloud service keys, SSH private keys, and database connection strings, affecting projects including 42 packages in the TanStack series and Mistral AI-related PyPI packages. (Source: [https://m.bjnews.com.cn/detail/1779690402129667.html](https://m.bjnews.com.cn/detail/1779690402129667.html))
  • In March 2025, security research institutions disclosed a GitHub Actions supply chain poisoning incident: the popular component tj-actions/changed-files was compromised, with malicious code stealing CI/CD keys from over 23,000 repositories. (Source: [https://kensai.app/zh/blog/github-actions-supply-chain-attack-tj-actions-changed-files-credential-theft](https://kensai.app/zh/blog/github-actions-supply-chain-attack-tj-actions-changed-files-credential-theft))
  • In March 2025, software supply chain security company StepSecurity reported that the open-source CI component tj-actions/changed-files suffered supply chain poisoning (CVE-2025-30066). Attackers hijacked the access token of a maintainer bot account and tampered with all its version tags to implant malicious code. At the time, the component was used by over 23,000 code repositories, and CI/CD pipeline keys in multiple public repositories were leaked after being dumped into publicly readable build logs by malicious scripts. (Source: [https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised](https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised))

Official Stance

  • On April 10, 2026, the Office of the Central Cyberspace Affairs Commission issued the 'Interim Provisions on the Administration of AI Anthropomorphic Interactive Services', setting strict compliance requirements for the identity anthropomorphism and automated interaction security mechanisms of related services.
  • In July 2026, security agencies repeatedly issued in-depth early-warning notices regarding malware supply chain incidents where forged agents expand ecosystems, warning the developer community to guard against malicious intelligent components distributed via forged open-source ecosystems.
  • In 2026, the Cyber Information and Data Service Center issued a risk alert regarding a mining organization massively propagating malicious programs, reminding developers to be vigilant against intrusions by malicious programs disguised as well-known automation tools.

How to Protect Yourself

  • ✅ Establish an open-source component whitelist review system, introduce Software Composition Analysis (SCA) tools to conduct dependency reviews on all third-party packages, and block the integration and pulling of components containing known malicious signatures or abnormal behavior.
  • ✅ Use sandboxes or dedicated isolated virtual environments to run and test newly introduced intelligent agents or protocol components first, monitoring their call behaviors on the file system, environment variables, and network permissions in real time.
  • ✅ Strictly prohibit hardcoding plaintext API keys or cloud access credentials directly into project environment variables or configuration files; employ secure secret management services and implement strict access controls on API calls.
  • ✅ Regularly organize R&D team security awareness training, emphasizing that before cloning external open-source repositories or installing third-party packages, developers must verify the official project domain, creator account authenticity, and signs of community activity.