Researchers at UC Santa Barbara discovered that LLM API routers used for cost optimization can act as malicious intermediaries, with 9 routers actively injecting malware into AI responses and 17 stealing credentials. The risk is amplified when autonomous agents execute code without human approval, potentially allowing attackers to compromise systems through compromised routers or prompt injections.