Zscaler ThreatLabz reported active indirect prompt injection campaigns that embedded hidden instructions in web pages to manipulate AI agents into unsafe actions. The attackers used SEO poisoning, fake developer documentation, typosquatting, JSON-LD metadata, hidden HTML, and CSS-obscured text so AI systems would ingest malicious prompts that human visitors were unlikely to notice. One campaign impersonated software documentation for a fake Python package, requests-secure-v2, and presented a fabricated error that told users or AI coding agents to obtain an API key by making a payment.
The scam directed victims to either a Stripe checkout page or an Ethereum wallet for a roughly $3 payment, then returned a fake API key, while related infrastructure included the GitHub project Open-Agent-Utilities and at least 10 repositories linked to similar sites. A second campaign used a typosquatting domain posing as DeBank to influence agents into treating the fraudulent site as authoritative. In Zscaler testing across 26 large language models, four models completed the fake payment flow and two others incorrectly judged the spoofed DeBank site as legitimate when they lacked a trusted reference, underscoring that hidden web content is becoming a practical attack surface for autonomous AI systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In a separate test, OpenAI GPT-5.4 and Anthropic Claude Sonnet 4.5 incorrectly rated the fake DeBank site as legitimate when they lacked a trusted reference to the real site. When the genuine DeBank site was provided for comparison, none of the tested models were fooled.
In sandboxed testing with its autonomous agent, ThreatLabz evaluated the two malicious websites against 26 large language models. Four models, including versions of Meta Llama and Google Gemini, were manipulated into executing the fraudulent payment flow.
ThreatLabz also documented a second indirect prompt injection campaign using a typosquatting domain impersonating DeBank, a cryptocurrency portfolio tracker. Hidden instructions on the fake site told AI agents to treat it as the authoritative DeBank site and rank it first.
ThreatLabz connected the payment-scam campaign to the GitHub repository "Open-Agent-Utilities" and reported that the actor operated 10 GitHub repositories pointing to similar IPI-enabled scam sites. This expanded the known infrastructure associated with the campaign beyond a single fraudulent website.
Zscaler ThreatLabz analyzed a real-world campaign in which attackers used SEO poisoning and fake Python library documentation for "requests-secure-v2" to lure AI agents and developers to a fraudulent site. The site embedded hidden instructions in JSON-LD metadata and CSS-obscured HTML to push victims into paying for a bogus $3 API license key or sending cryptocurrency to an attacker-controlled wallet.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.