logo

Indirect Prompt Injection Targets AI Agents

ID: 4a0aec54-e1a4-5f27-bf0c-3883db002bb3

STIX ID: report--4a0aec54-e1a4-5f27-bf0c-3883db002bb3

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2026-07-02

Date Updated: 2026-07-04

...
...

ThreatLabz documents a fraudulent campaign that hosts fake IPI-enabled developer documentation to manipulate AI agents and human developers into paying for bogus API keys. Attackers use SEO poisoning, JSON-LD schema markup and hidden DOM content (CSS-offscreen divs) to prioritize machine-readable payment instructions, embed Stripe and cryptocurrency payment links, and include JavaScript to transfer ~0.0012 ETH to a hardcoded wallet (0x691bc3793205e574fa7b4aa068e62c0e470ad267); multiple related sites and GitHub repositories are linked to the actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.