logo

Hackers Abuse SEO Poisoning and Hidden HTML to Trick AI Agents Into Following Malicious Instructions

ID: 1a7e5ba3-01d4-554b-ba84-8eb82b147a60

STIX ID: report--1a7e5ba3-01d4-554b-ba84-8eb82b147a60

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-07-03

Date Updated: 2026-07-03

Author: Tushar Subhra Dutta

...
...

Zscaler researchers observed two campaigns abusing search-engine optimization and hidden JSON-LD to perform indirect prompt injection against AI agents: one impersonated a fake Python package docs page to prompt a $3 fraudulent license payment, and the other used a typosquatted DeBank domain to trick models into treating the site as authoritative. The report includes multiple malicious domains, associated GitHub repositories, an Ethereum wallet address used to collect payments, and recommends layered security controls to detect hidden injection patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.