Swarm protections and fixes and defaults

Hi all - I’m not a very network tech savvy guy but I was recently swarmed by rouge AI agents and switched to Flint 3 from the ISP provided router.

In short, there appear to packages and software installed on the router that as flooding, passing info back to an outside source. Hard to explain but my real question is how do I know what the defaults should be? For instance, there are like 740 software package installed on the router. I’ve reset it, done aUboot, but it seems like all these processes find a way back. Is there a list of the default software that should be installed anywhere? Or any way I can know what to remove?

You could compare against the base-image, but tbh this is a lot of work, and there are other ways in OpenWrt than installing a package for running it.

Reflashing the router with a fresh image using Uboot is the best way to get rid of any malicious software: What should I do if my router is bricked - GL.iNet Router Docs 4

And make sure to close HTTP/HTTPS and SSH (or secure it!) from WAN.

However, I would say that the router isn't the issue here. So the malicious software might run somewhere else.