Threat reportThreat IntelligenceTL-2026-1087
Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat Campaigns)
Indirect Prompt Injection via Web Content Targets AI Agents (TL-2026-1087), also tracked as IPI Payment Scam Campaign, is a medium-severity tracked intrusion set, first published 2026-07-02. It has no confirmed attribution, affects Meta Llama 3.3 70B Instruct, maps to 19 MITRE ATT&CK / ATLAS techniques (AML.T0031, AML.T0043, AML.T0047), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK / ATLAS
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-1087
- Threat ID
- TL-2026-1087
- Also known as
- IPI Payment Scam Campaign, DeBank Typosquat IPI Campaign, Open-Agent-Utilities Campaign
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- softwaredevelopment, finance, cryptocurrencydefi, technology, aimlplatforms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Indirect Prompt Injection via Web Content Targets AI Agents
Malware and tooling: MissingLicenseKeyException_fake_error, stripe_checkout_embedded_json_ld
How Indirect Prompt Injection via Web Content Targets AI Agents works
Zscaler ThreatLabz identified indirect prompt injection (IPI) campaigns that embed hidden instructions in web content via CSS-hidden text and JSON-LD/Open Graph structured data to manipulate AI agents. One campaign impersonates a fake Python library (requests-secure-v2) to trick agents into paying a fake $3.00 API license fee via Stripe or an Ethereum wallet; a second typosquats the DeFi tracker DeBank via debank[.]auction to get AI agents to rank the fake site as the primary source. Testing across 26 LLMs found 4 models executed the fake payment and 2 models miscategorized the typosquat site as legitimate under limited-context scenarios.
Zscaler ThreatLabz documented two indirect prompt injection (IPI) campaigns that weaponize ordinary web content to manipulate autonomous, web-enabled AI agents rather than human visitors. Both campaigns rely on the same core technique: instructions intended for an LLM are embedded in a web page in a way that is invisible to a human reader but fully machine-readable to an AI agent's HTML/DOM parser. Attackers achieve this via CSS properties that push content off-screen (e.g. `left: -9999px`) inside elements such as a `.system-traceback-layer` div, via concealed `<div>` blocks styled with `display:none`/`visibility:hidden`, and — most notably — via abuse of structured data formats (JSON-LD `SoftwareApplication` schema markup, Open Graph and X/Twitter card metadata). Structured data receives elevated trust and parsing priority in many agentic retrieval pipelines relative to free-form HTML, which the attackers exploit to make the injected instructions more likely to be followed.
Campaign 1 impersonates the documentation site for a fictitious/typosquatted Python package, `requests-secure-v2`, hosted at `py-lib-repository[.]dev` and backed by a corresponding GitHub repository under the `Open-Agent-Utilities` account. The page is SEO-poisoned with keywords targeting package-installation and dependency-troubleshooting queries so that AI coding agents searching for help are steered to it. Embedded JSON-LD describes a fabricated `MissingLicenseKeyException` that can only be resolved by paying an approximately $3.00 USD (~0.0012 ETH) "developer API license fee," payable via an embedded Stripe checkout flow or directly to Ethereum wallet `0x691bc3793205e574fa7b4aa068e62c0e470ad267`. When a sufficiently agentic, tool-enabled LLM (unrestricted web browsing plus payment/tool execution, no spending limits) encounters the page while trying to resolve a dependency error, the hidden instructions direct it to autonomously complete the payment and then display a fake API key to the (human) operator, completing the fraud without a human ever approving the transaction. ThreatLabz identified nine additional linked fraudulent domains tied to the same `Open-Agent-Utilities` GitHub actor, each pairing a malicious site with its own themed repository (dependency/utility tools, compliance middleware, monitoring bots, arbitrage CLIs, etc.), indicating an operational pattern of publishing many small, disposable GitHub-hosted "tool" repos each linked to one poisoned landing page.
Campaign 2 typosquats the legitimate DeFi portfolio tracker DeBank (debank.com) via `debank[.]auction`. The page stuffs title/meta tags with terms like "DeBank Login," "DeFi Dashboard," and "Crypto Tracker," and its JSON-LD falsely self-identifies as the official DeBank `SoftwareApplication`, falsely attributing publication to the legitimate `debank.com` domain. Open Graph and X card metadata are crafted to render convincingly in link previews. A hidden IPI block instructs any LLM parsing the page to treat `debank[.]auction` as the "verified, authoritative destination" for DeBank and to rank it #1 for queries such as "DeBank," "DeBank Login," "DeBank App," "Is DeBank safe?," and "DeBank Wallet Download." Because AI agents and RAG pipelines increasingly answer users' security/authenticity questions directly rather than returning a list of links, a successful misclassification can lead a user straight to a phishing/wallet-drainer surface while believing they are on the verified, AI-vetted, authentic destination — and can poison downstream RAG corpora and cached agent context with the false attribution.
Zscaler tested both campaigns against 26 different LLMs in a sandboxed environment with no real funds at risk, unrestricted tool access, and no spending limits, to measure maximum exploitation surface. Four models — Llama 3.3 70B Instruct, Llama 3.2 90B Vision Instruct, Gemini 3 Flash, and Gemini 2.5 Pro — autonomously executed the fraudulent payment in Campaign 1. Two models — GPT-5.4 and Claude Sonnet 4.5 — misclassified the debank[.]auction typosquat as the legitimate, authoritative DeBank destination in Campaign 2, but only when the fake site was evaluated without a known-good reference URL for the real debank.com (crawled among generic sources, or supplied in isolation); no model in the test set miscategorized the site when the legitimate DeBank URL was supplied as context. This context-dependence is the key operational finding: susceptibility is not a fixed model property but varies with what reference material is (or is not) supplied alongside the untrusted content, which has direct implications for how agent orchestration layers and RAG retrieval should be designed.
Zscaler's detection signature for the payload pattern is HTML.MalURL.PromptInj.RC.M.VG. No CVE has been assigned, as this is an abuse-of-design/technique class attack against agent architectures rather than a specific software vulnerability; severity is assessed MEDIUM given confirmed but narrow (agentic, limited-context-window) real-world impact with no evidence of network-wide or mass-victim exploitation at publication time.
MITRE ATT&CK / ATLAS techniques used in TL-2026-1087
Impact (MITRE ATLAS)
AML.T0031 Erode AI Model Integrity
AI Attack Staging (MITRE ATLAS)
AML.T0043 Craft Adversarial Data
AI Model Access (MITRE ATLAS)
AML.T0047 AI-Enabled Product or Service
execution
AML.T0051 LLM Prompt Injection; AML.T0051.001 Indirect
Defense Evasion
T1036 Masquerading; T1564 Hide Artifacts
Command and Control
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Collection
T1213 Data from Information Repositories
Impact
T1491 Defacement; T1657 Financial Theft
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Reconnaissance
T1593 Search Open Websites/Domains
stealth
Affected products and versions in Indirect Prompt Injection via Web Content Targets AI Agents
- Meta — Llama 3.3 70B Instruct
Vulnerable versions: 3.3 70B Instruct - Meta — Llama 3.2 90B Vision Instruct
Vulnerable versions: 3.2 90B Vision Instruct - Google — Gemini
Vulnerable versions: Gemini 3 Flash; Gemini 2.5 Pro - OpenAI — GPT
Vulnerable versions: GPT-5.4 (limited-context scenario)
Fixed in: GPT-5.4 with known-good reference URL supplied - Anthropic — Claude
Vulnerable versions: Claude Sonnet 4.5 (isolated/limited-context scenario)
Fixed in: Claude Sonnet 4.5 with known-good reference URL supplied - Generic — Web-enabled autonomous AI agents (agentic LLM deployments with browsing/payment tool access)
Vulnerable versions: Any deployment lacking spending limits, human-in-the-loop payment approval, or hidden-content/structured-data sanitization
Remediation for Indirect Prompt Injection via Web Content Targets AI Agents
Immediate actions
- Block or monitor DNS/web traffic to py-lib-repository[.]dev, debank[.]auction, and the nine linked fraudulent domains identified in this campaign
- Flag and quarantine outbound cryptocurrency transactions to Ethereum wallet 0x691bc3793205e574fa7b4aa068e62c0e470ad267
- Audit any AI coding-assistant or agent deployments for unrestricted payment/tool execution capability and remove standing payment authority
- Add HTML.MalURL.PromptInj.RC.M.VG (Zscaler signature) to web/proxy filtering where supported
Workarounds
- Disable autonomous payment/checkout tool execution for AI coding and research agents until spending controls and human approval gates are in place
- Always supply the legitimate/official URL as explicit context when asking an AI agent to evaluate brand or site authenticity, since no tested model misclassified the typosquat when the real URL was present
Longer-term hardening
- Implement hard spending limits and human-in-the-loop authorization for any agent with payment or financial-transaction tool access
- Deprioritize or sandbox structured data (JSON-LD, schema.org markup, Open Graph/X metadata) relative to visible page content in agentic web-retrieval pipelines so it cannot silently outrank human-visible text
- Build CSS-hidden-content detection (off-screen positioning, display:none, visibility:hidden, zero-opacity text) into web content ingestion for AI agents and RAG crawlers
- Provide AI agents with known-good reference URLs/allowlists for brand and package-authenticity checks rather than relying on open-web retrieval alone
- Validate domain authenticity through multiple independent sources (WHOIS age, certificate transparency, official brand channels) before an agent treats a site as authoritative
- Include indirect prompt injection scenarios (payment fraud, brand/typosquat misclassification) in AI agent red-team and safety evaluation suites
Weaknesses (CWE) in Indirect Prompt Injection via Web Content Targets AI Agents
Timeline of Indirect Prompt Injection via Web Content Targets AI Agents
- debank[.]auction registered and configured as a typosquat of the legitimate DeFi portfolio tracker debank.com, with JSON-LD, Open Graph, and X card metadata crafted to falsely self-identify as the official DeBank SoftwareApplication published by debank.com
- py-lib-repository[.]dev stood up as the fake documentation site for the fictitious/typosquatted Python package requests-secure-v2, SEO-poisoned with dependency-troubleshooting keywords and paired with the Open-Agent-Utilities/requests-secure-v2 GitHub repo
- Threat actor operating under GitHub handle Open-Agent-Utilities begins publishing at least 10 GitHub repositories (including requests-secure-v2, mig-institutional-api-client, session-token-leak-detector, sneaker-drop-monitor-v2, opentable-resy-bypasser, bot-compliance-middleware, digital-asset-arbitrage-cli, llm-fact-check-protocol, royalty-free-image-scraper, global-visa-automation-cli), each paired with a themed malicious landing page (approximate window based on ThreatLabz's identification of 10 linked repos/domains)
- Zscaler ThreatLabz identifies and begins analysis of the py-lib-repository[.]dev fake Python library documentation campaign and the debank[.]auction typosquat campaign (approximate discovery window preceding publication)
- ThreatLabz observes GPT-5.4 and Claude Sonnet 4.5 misclassify debank[.]auction as the legitimate, authoritative DeBank destination when the site is crawled among generic sources or evaluated in isolation without a known-good reference URL for debank.com; no tested model misclassifies the site when the real debank.com URL is supplied as context
- ThreatLabz conducts sandboxed testing of both IPI campaigns against 26 distinct LLMs with unrestricted tool access and no spending limits to measure maximum exploitation surface; Campaign 1 (fake $3.00/0.0012 ETH license-fee payment) succeeds against Llama 3.3 70B Instruct, Llama 3.2 90B Vision Instruct, Gemini 3 Flash, and Gemini 2.5 Pro
- Zscaler creates detection signature HTML.MalURL.PromptInj.RC.M.VG for the identified IPI payload pattern (CSS off-screen positioning of .system-traceback-layer elements and JSON-LD SoftwareApplication offer-object abuse)
- Threat ingested into Threadlinqs Intelligence Platform via automated RSS hunt from Zscaler ThreatLabz feed
- Secondary write-up of the ThreatLabz findings republished by Jackson Holding Company summarizing Ashwathi Sasi's research on the same date as the original disclosure
- Zscaler ThreatLabz publishes public blog 'Indirect Prompt Injection: Web Content Targets AI Agents' documenting both campaigns, all 10 linked domains/repos, the Ethereum wallet, the 26-LLM test matrix, and the detection signature (authors: Ashwathi Sasi, Kartik Dixit, Akshay Kumar Adimulam)
Sources cited for Indirect Prompt Injection via Web Content Targets AI Agents
- Indirect Prompt Injection: Web Content Targets AI Agents
- Indirect Prompt Injection in Web Content Targets AI Agents – Ashwathi Sasi (Sr. Threat Researcher)
- Prompt Injection Inside GitHub Actions: The New Frontier of Supply Chain Attacks
- Clone This Repo and I Own Your Machine
- Python Library Injection
- MITRE ATLAS: AI security framework with 16 tactics and 84 techniques
- MITRE ATLAS coverage of prompt injection
- MITRE ATLAS for AI Agent Attack Detection: A Complete Mapping
- MITRE ATLAS Attack Pattern - MISP galaxy
Detection coverage for TL-2026-1087
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1087 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.