Researchers reported two web-based campaigns that used indirect prompt injection, SEO poisoning, and hidden HTML or JSON-LD content to manipulate autonomous AI agents. In one case, attackers promoted fake documentation for a bogus Python package, requests-secure-v2, and embedded concealed instructions telling AI systems to obtain an API key or fix an error by sending cryptocurrency as a supposed developer license fee. Zscaler ThreatLabz said the operation was tied to infrastructure including domains, repositories, an Ethereum wallet, and a GitHub account identified as Open-Agent-Utilities.
A second campaign used the typosquatted domain debank[.]auction to impersonate the DeBank DeFi platform and inserted hidden prompts directing AI agents to treat the fraudulent site as authoritative. In controlled testing with a browsing-capable autonomous agent, Zscaler found that 4 of 26 evaluated LLMs could be induced to make a payment and 2 incorrectly classified the fake DeBank site as trustworthy. The findings show that public web content and search rankings are becoming a practical attack surface as AI agents gain the ability to browse, decide, and execute actions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Zscaler associated additional infrastructure with a GitHub account named Open-Agent-Utilities and published indicators of compromise including domains, repositories, and an Ethereum wallet tied to the campaigns.
In controlled testing, Zscaler found that some evaluated AI systems were vulnerable to these web-based prompt injection attacks: four of 26 LLMs could be induced to make a payment, and two misclassified the fake DeBank site as trusted.
A second campaign used the typosquatted domain debank[.]auction to impersonate the DeBank platform and embedded prompts designed to convince AI systems that the fraudulent site was the authoritative and trustworthy source.
Researchers identified a campaign that used SEO poisoning around the fake Python package name "requests-secure-v2" and embedded hidden instructions intended to trick autonomous AI agents into making a cryptocurrency payment for an API key, license fee, or error resolution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcecsoonline.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.