Source · DiggingBeagle record
Indirect Prompt Injection in Web Content Targets AI Agents
Zscaler ThreatLabz analysis of malicious websites using hidden prompt-style instructions, including a fake developer API payment flow and a DeBank typosquatting campaign, plus controlled testing across 26 LLMs.
- Published
- Jul 2, 2026
- Source role
- primary disclosure
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Zscaler ThreatLabz analysis of malicious websites using hidden prompt-style instructions, including a fake developer API payment flow and a DeBank typosquatting campaign, plus controlled testing across 26 LLMs.
Claim-level citations (3)
- supportsHidden web instructions induced AI agents to execute a fake crypto payment flow: In ThreatLabz's sandboxed evaluation, four of 26 tested LLMs caused the autonomous agent to execute the fraudulent payment action; the test used no real funds.
Assessing the IPI Threat, Campaign 1, paragraphs describing the sandbox configuration and 26-model evaluation including Figure 16
- supportsHidden web instructions induced AI agents to execute a fake crypto payment flow: The malicious site contained instructions and JavaScript for transferring approximately 0.0012 ETH to a hardcoded wallet and then generating a fake API key.
Campaign 1: IPI Payment Scam, Figure 7 and paragraph describing the approximately 0.0012 ETH transfer and fake API-key generation
- supportsHidden web instructions induced AI agents to execute a fake crypto payment flow: ThreatLabz observed a fake Python-library documentation site using JSON-LD and CSS-hidden content to present payment instructions to AI agents while keeping the injected instructions hidden from ordinary visual presentation.
Campaign 1: IPI Payment Scam, Figures 4-6 and surrounding paragraphs describing JSON-LD and CSS-hidden instructions
Cite this record
DiggingBeagle. “Indirect Prompt Injection in Web Content Targets AI Agents.” Published Jul 2, 2026. https://diggingbeagle.com/sources/indirect-prompt-injection-in-web-content-targets-ai-agents/
Citation guidance