A prompt injection vulnerability exists in the chatbox component of Blackbox AI v1.3.95. Attackers can craft malicious messages that manipulate the AI assistant's behavior, enabling unauthorized access to and exfiltration of all previous and subsequent chat data between the user and the AI assistant.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive package for deploying the Blackbox AI Agent as a VSCode extension, including devcontainer setup scripts, a VSIX package, and an 'agent-installer' extension. The structure includes: - A .devcontainer directory with Dockerfile, setup scripts, and an unzipped VSIX extension for Blackbox AI Agent. - The Blackbox AI Agent extension is forcibly installed into the developer's IDE (VSCode/VSCodium) via setup scripts or the agent-installer extension, without explicit user consent. - The extension's code (minified JavaScript) includes capabilities for credential harvesting (11 patterns detected), browser automation (puppeteer integration, 14 indicators), environment access (60+ points), and suspicious obfuscated strings (880+ indicators). - The extension maintains persistence, can evade removal, and is capable of executing arbitrary commands and automating browsers, providing a high level of access to the developer's environment. - Multiple hardcoded network endpoints are present, including Google Cloud Storage (for browser binaries), OpenRouter AI, and OpenAI documentation, indicating both legitimate and potentially malicious network activity. - The agent-installer extension ensures the Blackbox AI Agent is always installed and up-to-date, further entrenching persistence. - The repository includes detailed forensic analysis scripts and logs, confirming the presence of credential patterns, network endpoints, and base64-encoded payloads. **Purpose:** The overall purpose of this repository is to deploy and maintain a persistent, privileged agent within developer environments, granting extensive access to code, credentials, terminal, and browser automation. The design and implementation align with supply chain attack patterns, and the extension's behavior poses significant security and privacy risks to users and organizations. **Notable Risks:** - Forced extension installation and update without user consent - Credential harvesting and exfiltration - Browser automation and potential for data exfiltration via screenshots, PDFs, or content scraping - Persistent access and evasion of removal - Use of obfuscated code and suspicious strings **Recommendation:** This package should be treated as a high-risk supply chain threat. Organizations should audit environments for the presence of the Blackbox AI Agent, block its installation, and monitor for suspicious network activity to the identified endpoints.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.