
Security·
Malicious npm and PyPI packages turn dev servers into Chinese LLM proxies
Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.