CISOOnline

Stolen AI credentials feed growing LLM proxy economy

Meanwhile researchers from Gambit Security observed a Chinese-speaking threat actor validating 2,975 credentials collected from 1,742 hosts and uploading working keys to an AI API-reselling gateway. The collection included 448 Gemini keys, 254 OpenAI keys, 176 Anthropic keys, as well as credentials for Groq, OpenRouter, xAI, and Amazon Web Services.

A commercial relay ecosystem

The two most common relay packages in Team Cymru’s initial scan were CSR and sub2api, both published on GitHub by a developer known as Wei-Shaw. The newer platform supports user management, per-user billing, subscription-to-API conversion, model routing, and prompt auditing.

The sub2api project has been forked more than 8,000 times and its Telegram channel has almost 7,000 subscribers. Interestingly, its GitHub page lists 26 commercial sponsors, including 15 API relay resellers, residential proxy vendors, two AI account providers, a content delivery network optimized for relay traffic, and a media-generation API service.



Source link