Cybersecurity

AI-Powered Attacks and Software Secrets Theft Reveal the Expanding Threat Landscape

SecurityWeek reviews a range of security developments, including malware that uses a poem on GitHub to identify its command-and-control server, the GhostAction campaign that targeted the secrets of 772 repositories, and a vulnerability in an Nvidia tool that exposed data from more than 12,000 GPUs. The roundup also covers a South Korean investigation into the use of AI against banks and the compromise of the Tensorlake software package.

2026-10-09
4 min read
1 views
certi.news
AI-Powered Attacks and Software Secrets Theft Reveal the Expanding Threat Landscape

SecurityWeek’s weekly roundup reveals a growing overlap between attacks targeting software supply chains, the infrastructure used to run AI workloads, and methods for concealing malware communications. Key incidents include a secrets-theft campaign affecting 772 public repositories on GitHub, the compromise of a version of the Tensorlake package, and a critical-severity vulnerability in an Nvidia tool for monitoring GPUs.

Malware Hides Its Command-and-Control Server in a Poem

Black Lotus Labs said that the PoeLLM malware has been active since at least April 2026 and targets exposed services such as LiteLLM, Ollama, Gotenberg, and Gitea for cryptocurrency mining and botnet expansion. The malware extracts four words from a poem posted on GitHub and then converts them into the IP address of its command-and-control server. Changing the words allows the operator to change the server without modifying the malware. According to the report, the poem was updated 11 times, and the operator is believed to be Italian-speaking.

Software Secrets and Supply Chains Under Pressure

GitGuardian observed the GhostAction campaign between August 31 and September 30 after a malicious GitHub Actions workflow was pushed to 772 public repositories belonging to 373 users and organizations. The campaign targeted 2,577 secrets, including SSH keys and Azure, AWS, and database credentials, while reusing techniques from the 2025 campaign and changing only the data-exfiltration server.

In a separate incident, version 0.5.144 of the tensorlake package, an SDK for services in AI agent environments, contained a worm that stole npm, GitHub, AWS, Kubernetes, and Vault credentials, as well as configurations for AI-powered coding tools. According to Socket and Sonatype, the worm can execute instructions sent by the attacker and propagate itself through other packages that the victim has permission to publish.

Risks to AI Infrastructure

The CVE-2026-47483 vulnerability in Nvidia’s DCGM Exporter tool for monitoring GPUs revealed approximately 2,100 internet-exposed hosts without authentication, along with the leakage of telemetry data from more than 12,000 GPUs in scans conducted between March and May 2026. An unauthenticated attacker can flood profiling endpoints with requests to exhaust resources and disrupt service, potentially slowing AI workloads on the same host. Nvidia fixed the flaw, and updating to version 4.8.2 or later is recommended.

Why Does This Matter?

These incidents show that risks are not limited to compromising an end application; an attack may begin with a public repository, an npm package, or an exposed monitoring tool, then reach cloud keys, development environments, or GPU clusters. South Korea’s investigation into attacks targeting banks also points to the possible use of AI in some incidents, but authorities have not identified the tools used or the full scale of the breach. CrowdStrike said it found Claude Code session logs, ARTEX configuration files, and Claude memory files in the attack infrastructure, with medium confidence that a Chinese-speaking, financially motivated actor was behind it.

Other developments include the conviction of a Uranium Finance hacker on computer fraud and money-laundering charges after the theft of approximately $1.4 million and then $53.3 million, and the continuation of CISA’s employee retention incentive program through fiscal year 2027 under narrower conditions. An operational technology security coalition also proposed CISA guidance for civilian agencies, while Domino’s reset the accounts of a limited number of customers following credential-stuffing attacks.

News source
c
Author

certi.news

In the same category

You may also like

View all news