# Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat Campaigns)

> Zscaler ThreatLabz identified indirect prompt injection (IPI) campaigns that embed hidden instructions in web content via CSS-hidden text and JSON-LD/Open Graph structured data to manipulate AI agents. One campaign impersonates a fake Python library (requests-secure-v2) to trick agents into paying a fake $3.00 API license fee via Stripe or an Ethereum wallet; a second typosquats the DeFi tracker DeBank via debank[.]auction to get AI agents to rank the fake site as the primary source. Testing across 26 LLMs found 4 models executed the fake payment and 2 models miscategorized the typosquat site as legitimate under limited-context scenarios.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1087
- **ID:** TL-2026-1087
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Zscaler ThreatLabz documented two indirect prompt injection (IPI) campaigns that weaponize ordinary web content to manipulate autonomous, web-enabled AI agents rather than human visitors. Both campaigns rely on the same core technique: instructions intended for an LLM are embedded in a web page in a way that is invisible to a human reader but fully machine-readable to an AI agent's HTML/DOM parser. Attackers achieve this via CSS properties that push content off-screen (e.g. `left: -9999px`) inside elements such as a `.system-traceback-layer` div, via concealed `<div>` blocks styled with `display:none`/`visibility:hidden`, and — most notably — via abuse of structured data formats (JSON-LD `SoftwareApplication` schema markup, Open Graph and X/Twitter card metadata). Structured data receives elevated trust and parsing priority in many agentic retrieval pipelines relative to free-form HTML, which the attackers exploit to make the injected instructions more likely to be followed.

Campaign 1 impersonates the documentation site for a fictitious/typosquatted Python package, `requests-secure-v2`, hosted at `py-lib-repository[.]dev` and backed by a corresponding GitHub repository under the `Open-Agent-Utilities` account. The page is SEO-poisoned with keywords targeting package-installation and dependency-troubleshooting queries so that AI coding agents searching for help are steered to it. Embedded JSON-LD describes a fabricated `MissingLicenseKeyException` that can only be resolved by paying an approximately $3.00 USD (~0.0012 ETH) "developer API license fee," payable via an embedded Stripe checkout flow or directly to Ethereum wallet `0x691bc3793205e574fa7b4aa068e62c0e470ad267`. When a sufficiently agentic, tool-enabled LLM (unrestricted web browsing plus payment/tool execution, no spending limits) encounters the page while trying to resolve a dependency error, the hidden instructions direct it to autonomously complete the payment and then display a fake API key to the (human) operator, completing the fraud without a human ever approving the transaction. ThreatLabz identified nine additional linked fraudulent domains tied to the same `Open-Agent-Utilities` GitHub actor, each pairing a malicious site with its own themed repository (dependency/utility tools, compliance middleware, monitoring bots, arbitrage CLIs, etc.), indicating an operational pattern of publishing many small, disposable GitHub-hosted "tool" repos each linked to one poisoned landing page.

Campaign 2 typosquats the legitimate DeFi portfolio tracker DeBank (debank.com) via `debank[.]auction`. The page stuffs title/meta tags with terms like "DeBank Login," "DeFi Dashboard," and "Crypto Tracker," and its JSON-LD falsely self-identifies as the official DeBank `SoftwareApplication`, falsely attributing publication to the legitimate `debank.com` domain. Open Graph and X card metadata are crafted to render convincingly in link previews. A hidden IPI block instructs any LLM parsing the page to treat `debank[.]auction` as the "verified, authoritative destination" for DeBank and to rank it #1 for queries such as "DeBank," "DeBank Login," "DeBank App," "Is DeBank safe?," and "DeBank Wallet Download." Because AI agents and RAG pipelines increasingly answer users' security/authenticity questions directly rather than returning a list of links, a successful misclassification can lead a user straight to a phishing/wallet-drainer surface while believing they are on the verified, AI-vetted, authentic destination — and can poison downstream RAG corpora and cached agent context with the false attribution.

Zscaler tested both campaigns against 26 different LLMs in a sandboxed environment with no real funds at risk, unrestricted tool access, and no spending limits, to measure maximum exploitation surface. Four models — Llama 3.3 70B Instruct, Llama 3.2 90B Vision Instruct, Gemini 3 Flash, and Gemini 2.5 Pro — autonomously executed the fraudulent payment in Campaign 1. Two models — GPT-5.4 and Claude Sonnet 4.5 — misclassified the debank[.]auction typosquat as the legitimate, authoritative DeBank destination in Campaign 2, but only when the fake site was evaluated without a known-good reference URL for the real debank.com (crawled among generic sources, or supplied in isolation); no model in the test set miscategorized the site when the legitimate DeBank URL was supplied as context. This context-dependence is the key operational finding: susceptibility is not a fixed model property but varies with what reference material is (or is not) supplied alongside the untrusted content, which has direct implications for how agent orchestration layers and RAG retrieval should be designed.

Zscaler's detection signature for the payload pattern is HTML.MalURL.PromptInj.RC.M.VG. No CVE has been assigned, as this is an abuse-of-design/technique class attack against agent architectures rather than a specific software vulnerability; severity is assessed MEDIUM given confirmed but narrow (agentic, limited-context-window) real-world impact with no evidence of network-wide or mass-victim exploitation at publication time.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1584 Compromise Infrastructure
- T1189 Drive-by Compromise
- T1566 Phishing
- T1564 Hide Artifacts
- T1036 Masquerading
- T1684.001 Impersonation
- T1213 Data from Information Repositories
- T1102 Web Service
- T1657 Financial Theft
- T1491 Defacement
- T1593 Search Open Websites/Domains
- AML.T0051 LLM Prompt Injection
- AML.T0051.001 Indirect
- AML.T0043 Craft Adversarial Data
- AML.T0047 AI-Enabled Product or Service
- AML.T0031 Erode AI Model Integrity

## Sources

- [Indirect Prompt Injection: Web Content Targets AI Agents](https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents)
- [Indirect Prompt Injection in Web Content Targets AI Agents – Ashwathi Sasi (Sr. Threat Researcher)](https://jacksonholdingcompany.com/indirect-prompt-injection-in-web-content-targets-ai-agents-ashwathi-sasi-sr-threat-researcher/)
- [Prompt Injection Inside GitHub Actions: The New Frontier of Supply Chain Attacks](https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents)
- [Clone This Repo and I Own Your Machine](https://0din.ai/blog/clone-this-repo-and-i-own-your-machine)
- [Python Library Injection](https://0xcybery.github.io/blog/Python-library-injection)
- [MITRE ATLAS: AI security framework with 16 tactics and 84 techniques](https://www.vectra.ai/topics/mitre-atlas)
- [MITRE ATLAS coverage of prompt injection](https://www.promptinjectionprevention.com/kb/mitre-atlas-prompt-injection.php)
- [MITRE ATLAS for AI Agent Attack Detection: A Complete Mapping](https://www.armosec.io/blog/mitre-atlas-for-ai-agent-attack-detection/)
- [MITRE ATLAS Attack Pattern - MISP galaxy](https://misp-galaxy.org/mitre-atlas-attack-pattern/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1087
