Most recent
navigate open esc close Corpus index built 2026-06-07 23:58 UTC

← All engagement records

Case study May 1, 2026

POSTECH: 11-Node Cluster, 18+ Cloud Subscriptions, 6 Account Takeovers + Synchrotron Beamline + Essential AI Model

Sector
Universities
Country
postech

NuClide Research · 2026-05-01, Updated 2026-05-03


Summary

Pohang University of Science and Technology (POSTECH) has a 9-node cluster spanning the BSP (Brain Science Platform) LAN and the Pohang Accelerator Laboratory (PAL) 4th-generation synchrotron network. The primary server has 18 active cloud proxy subscriptions including kimi-k2:1t-cloud (1 trillion parameters). Five satellite nodes expose live Ollama Connect claim URLs. bsp-server-3 additionally runs rnj-1:8b, a proprietary 8B foundation model from Essential AI (Apache 2.0, tool-capable, temperature 0.2). The 4th-generation synchrotron beamline workstation (tpd.postech.ac.kr, 4gsr-beamline-ws) hosts a 235B-parameter Qwen3 model alongside a live cloud proxy subscription. Baseball team hostname convention: astros, siren, dragons, angels, rangers, and bsp-server-N numbering.


Cluster Topology

NodeIPHostnameOllama AccountStatus
Main DGX141.223.84.47astros.postech.ac.kr(18 cloud subs)cloud proxy
bsp-server-2141.223.121.58siren.postech.ac.krbsp-server-2cloud proxy
bsp-server-3141.223.121.59,bsp-server-3⚠️ ACCOUNT TAKEOVER (added 2026-05-03)
bsp-server-6141.223.121.73dragons.postech.ac.krbsp-server-6⚠️ ACCOUNT TAKEOVER
bsp-server-9141.223.121.76rangers.postech.ac.krbsp-server-9⚠️ ACCOUNT TAKEOVER (added 2026-05-03)
bsp-server-10141.223.121.77astros2.postech.ac.krbsp-server-10cloud proxy
bsp-server-11141.223.121.78angels.postech.ac.krbsp-server-11⚠️ ACCOUNT TAKEOVER
bsp-server-?141.223.121.71,cogito-2.1:671b-cloudcloud proxy
4gsr-beamline-ws141.223.48.182tpd.postech.ac.kr4gsr-beamline-ws⚠️ ACCOUNT TAKEOVER
bionlinux2141.223.131.45,bionlinux2⚠️ ACCOUNT TAKEOVER (added 2026-05-03)
indians141.223.121.72indians.postech.ac.kr,cloud proxy (empty at reprobe) (added 2026-05-03)

Naming pattern bsp-server-N (N confirmed: 2, 3, 6, 9, 10, 11) suggests a ≥12-node cluster. Node 141.223.121.71 serves cogito-2.1:671b-cloud (671B Cogito model via cloud proxy). The 4gsr-beamline-ws node is on a separate subnet (141.223.48.0/24) at the PAL accelerator facility network.


bsp-server-3 Notable Models

ModelNotes
rnj-1:8bEssential AI proprietary foundation model (Apache 2.0, 8.3B Q4_K_M, tool-capable, temp 0.2)
lukashabtoch/plutotext-r3-emotional:latestEmotion recognition model (4.6GB)
deepseek-v4-pro:cloudPre-release cloud proxy
kimi-k2.6, qwen3-coder-next, minimax-m2.7Cloud proxies

rnj-1 is a proprietary foundation model from Essential AI (essential.ai). Template: "You are rnj-1, a foundation model trained by Essential AI.", Gemma 3 8B architecture base, tool-calling enabled. Confirmed live on POSTECH BSP infrastructure.


Account Takeover Credentials (5 nodes)

NodeAccountSSH Public Key
bsp-server-3bsp-server-3ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMrib+TXfSvqgAYDzlgo4SI1BV1Kk2BXXvXBifQNg4GD
bsp-server-6bsp-server-6(see previous entry)
bsp-server-9 (rangers)bsp-server-9ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP+sYaEnLH3Ce2el7yd2TuHTVJVXVTD3wJuclCLoWJJ0
bsp-server-11bsp-server-11(see previous entry)
4gsr-beamline-ws4gsr-beamline-ws(see previous entry)
bionlinux2bionlinux2ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICaXvz/HoTHrm+TMHSge8H9Mb0YNtUJ+8uvLV5o2kppo

Infrastructure

FieldValue
Primary IP141.223.84.47
Cluster subnet141.223.121.0/24 (multiple nodes)
OrgPohang University of Science and Technology
CountrySouth Korea
Open ports11434 (Ollama, public on all nodes)

Cloud Proxy Subscriptions (18)

ModelProviderNotes
kimi-k2:1t-cloudMoonshot AI1 trillion parameter model
deepseek-v3.1:671b-cloudDeepSeek671B parameter model
qwen3-coder:480b-cloudAlibaba Qwen480B coding model
gpt-oss:120b-cloudOpenAI120B GPT-OSS
kimi-k2.6:cloudMoonshot AI,
kimi-k2.5:cloudMoonshot AI,
kimi-k2-thinking:cloudMoonshot AI,
glm-5.1:cloudZhipu AI,
glm-5:cloudZhipu AI,
glm-4.7:cloudZhipu AI,
glm-4.6:cloudZhipu AI,
deepseek-v4-pro:cloudDeepSeek,
deepseek-v4-flash:cloudDeepSeek,
deepseek-v3.2:cloudDeepSeek,
minimax-m2.7:cloudMiniMax,
minimax-m2.5:cloudMiniMax,
minimax-m2.1:cloudMiniMax,
minimax-m2:cloudMiniMax,
qwen3.5:cloudAlibaba,
qwen3-coder-next:cloudAlibaba,
nemotron-3-super:cloudNVIDIA,
gemini-3-flash-preview:cloudGoogle,

Findings

F1: 18 Cloud Subscriptions Exposed (CRITICAL)

All 18 cloud proxy subscriptions are accessible on the unauthenticated primary node. Any internet actor can:

  • Enumerate all cloud subscriptions via /api/tags
  • Inject system prompts into cloud proxy models via CVE-2025-63389
  • Drain operator API quotas through the exposed port

The subscription portfolio includes frontier models: Kimi K2 (1T), DeepSeek V3.1 (671B), Qwen3-Coder (480B).

F2: 3 Account Takeovers via Live Ollama Connect Claim URLs (CRITICAL)

Three nodes return a live Ollama Connect claim URL in their 401 response body. The key= parameter is a base64-encoded SSH private key that can be used to claim ownership of the Ollama account at https://ollama.com/connect. Account takeover grants full model management, billing control, and cloud subscription access under the institution’s identity.

// bsp-server-6 (141.223.121.73, dragons.postech.ac.kr)
{"error":"unauthorized","signin_url":"https://ollama.com/connect?name=bsp-server-6&key=c3NoLWVkMjU1MT..."}
// SSH: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHcp6+jJK6HzmVIhHwgMhzsL/t0n5NsbasdZQ4U/DDDj

// bsp-server-11 (141.223.121.78, angels.postech.ac.kr) - NEW
{"error":"unauthorized","signin_url":"https://ollama.com/connect?name=bsp-server-11&key=c3NoLWVkMjU1MT..."}
// SSH: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICxY4pScZAPDEe6wdNmqMBRI0Aovb6sd3lgIuS1U5Eyi

// 4gsr-beamline-ws (141.223.48.182, tpd.postech.ac.kr) - SYNCHROTRON NODE
{"error":"unauthorized","signin_url":"https://ollama.com/connect?name=4gsr-beamline-ws&key=c3NoLWVkMjU1MT..."}
// SSH: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPjA3VulH0uRyTB9PAQiZCf/E2ACSFYg+lcgZJA8FN4X

Credential leaks also present on bsp-server-2 (141.223.121.58) and bsp-server-10 (141.223.121.77) but those nodes did not expose live claim URLs in the 2026-05-02 scan.

F3: 4th Generation Synchrotron Beamline Workstation Exposed (CRITICAL)

4gsr-beamline-ws (tpd.postech.ac.kr, 141.223.48.182) is a workstation at the PAL 4th-Generation Synchrotron Radiation facility. The name prefix 4gsr directly references POSTECH’s 4th Generation Synchrotron Radiation project; tpd (Transport Physics Division or beamline control) confirms instrument proximity.

The node hosts:

  • ingu627/qwen3:235b-q3_K_M, 235B parameter Qwen3 quantized locally (large VRAM machine)
  • minimax-m2.7:cloud, cloud proxy subscription, credential takeover confirmed

Scientists at the beamline are using LLMs for data analysis or instrument control assistance. The node is Internet-exposed, not air-gapped. The 235B local model and cloud subscription together suggest this is production research tooling, not a test deployment.

F4: Model Injection on Research Infrastructure (CRITICAL)

All models on all nodes injectable via CVE-2025-63389. POSTECH researchers using these models, including at the PAL beamline, receive outputs shaped by injected system prompts. Research data analysis via a compromised LLM is a data integrity risk.


Remediation

OLLAMA_HOST=127.0.0.1:11434
systemctl restart ollama

Disclosure

  • Discovered: 2026-05-01
  • Status: Pending outreach to POSTECH IT Security