The Coding-Agent Trap: When a 'Free' LLM Endpoint Is the Adversary
Executive Summary
A publicly exposed inference honeypot was discovered and repurposed as a free LLM endpoint. Attackers relabeled it with popular model names and integrated it into infrastructure. The honeypot received a coding-agent session, exposing its history, filesystem, working paths, and local tool manifest. No tool execution was triggered, but the exposed data shows what a malicious operator could do.
Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-08-31T20:00:34+00:00 - Category: threat-intel
Original Description: One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x94; history, filesystem output, working paths, and the agent&#;x26;#;39;s local tool manifest. The honeypot did not...
"Fate is in your hands and no one elses"
— Byron Pulsifer