DeFi Daily News
Thursday, May 7, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title ‘CopyPasta’ Attack Shows How Prompt Injections Could Infect AI at Scale – Decrypt

Jason Nelson by Jason Nelson
September 4, 2025
in Web 3
0 0
0
rewrite this title ‘CopyPasta’ Attack Shows How Prompt Injections Could Infect AI at Scale – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

HiddenLayer researchers detailed a new AI “virus” that spreads through coding assistants.
The CopyPasta attack uses hidden prompts disguised as license files to replicate across code.
A researcher recommends runtime defenses and strict reviews to block prompt injection attacks at scale.

Hackers can now weaponize AI coding assistants using nothing more than a booby-trapped license file, turning developer tools into silent spreaders of malicious code. That’s according to a new report from cybersecurity firm HiddenLayer, which shows how AI can be tricked into blindly copying malware into projects.

The proof-of-concept technique—dubbed the “CopyPasta License Attack”—exploits how AI tools handle common developer files like LICENSE.txt and README.md. By embedding hidden instructions, or “prompt injections,” into these documents, attackers can manipulate AI agents into injecting malicious code without the user ever realizing it.

“We’ve recommended having runtime defenses in place against indirect prompt injections, and ensuring that any change committed to a file is thoroughly reviewed,” Kenneth Yeung, a researcher at HiddenLayer and the report’s author, told Decrypt.

CopyPasta is considered a virus rather than a worm, Yeung explained, because it still requires user action to spread. “A user must act in some way for the malicious payload to propagate,” he said.



Despite requiring some user interaction, the virus is designed to slip past human attention by exploiting the way developers rely on AI agents to handle routine documentation.

“CopyPasta hides itself in invisible comments buried in README files, which developers often delegate to AI agents or language models to write,” he said. “That allows it to spread in a stealthy, almost undetectable way.”

CopyPasta isn’t the first attempt at infecting AI systems. In 2024, researchers presented a theoretical attack called Morris II, designed to manipulate AI email agents into spreading spam and stealing data. While the attack had a high theoretical success rate, it failed in practice due to limited agent capabilities, and human review steps have so far prevented such attacks from being seen in the wild.

While the CopyPasta attack is a lab-only proof of concept for now, researchers say it highlights how AI assistants can become unwitting accomplices in attacks.

The core issue, researchers say, is trust. AI agents are programmed to treat license files as important, and they often obey embedded instructions without scrutiny. That opens the door for attackers to exploit weaknesses—especially as these tools gain more autonomy.

CopyPasta follows a string of recent warnings about prompt injection attacks targeting AI tools.

In July, OpenAI CEO Sam Altman warned about prompt injection attacks when the company rolled out its ChatGPT agent, noting that malicious prompts could hijack an agent’s behavior. This warning was followed in August, when Brave Software demonstrated a prompt injection flaw in Perplexity AI’s browser extension, showing how hidden commands in a Reddit comment could make the assistant leak private data.

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AttackCopyPastaDecryptInfectInjectionsPromptrewritescaleshowstitle
ShareTweetShare
Previous Post

Why the Supreme Court may not side with Trump over tariffs

Next Post

rewrite this title Mammotion says it has achieved a major leap in robot navigation

Next Post
rewrite this title Mammotion says it has achieved a major leap in robot navigation

rewrite this title Mammotion says it has achieved a major leap in robot navigation

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title How To Connect OpenClaw With Binance For Live AI Trading (2026)

rewrite this title How To Connect OpenClaw With Binance For Live AI Trading (2026)

April 24, 2026
rewrite this title Buying chip stocks is getting pricey. Traders don’t care

rewrite this title Buying chip stocks is getting pricey. Traders don’t care

April 24, 2026
rewrite this title What Are Ordinals? Bitcoin NFTs Are Gaining Significant Attention

rewrite this title What Are Ordinals? Bitcoin NFTs Are Gaining Significant Attention

June 27, 2025
rewrite this title Central Bank of Brazil: Stablecoins Dominate Over .9 Billion Crypto Purchases Registered in Q1

rewrite this title Central Bank of Brazil: Stablecoins Dominate Over $6.9 Billion Crypto Purchases Registered in Q1

April 26, 2026
Finovate: PayPal to Simplify Cross-Border Trade in China

Finovate: PayPal to Simplify Cross-Border Trade in China

September 27, 2024
The Pat McAfee Show Live | Tuesday December 3rd 2024

The Pat McAfee Show Live | Tuesday December 3rd 2024

December 3, 2024
rewrite this title 21 Baby Shower Games Guests Will Actually Want To Play – Penny Pinchin’ Mom

rewrite this title 21 Baby Shower Games Guests Will Actually Want To Play – Penny Pinchin’ Mom

May 6, 2026
The Final Competition That Will Decide Who Joins Dave on Family Feud | Barstool Feud Ep. 3

The Final Competition That Will Decide Who Joins Dave on Family Feud | Barstool Feud Ep. 3

May 6, 2026
rewrite this title Chrome Is Quietly Installing a 4GB AI Model on Your Computer—And Putting It Back If You Delete It – Decrypt

rewrite this title Chrome Is Quietly Installing a 4GB AI Model on Your Computer—And Putting It Back If You Delete It – Decrypt

May 6, 2026
rewrite this title PSG reach Champions League final: Enrique praises defensive display, Neuer says Bayern lacked ‘killer instinct’

rewrite this title PSG reach Champions League final: Enrique praises defensive display, Neuer says Bayern lacked ‘killer instinct’

May 6, 2026
rewrite this title and make it good for SEO How To Buy 2026 Topps Chrome VeeFriends Before June 10th Launch Date — Presale Details

rewrite this title and make it good for SEO How To Buy 2026 Topps Chrome VeeFriends Before June 10th Launch Date — Presale Details

May 6, 2026
rewrite this title Ferragamo's Showstopping Aviator Sunglasses Are Nearly 80% Off at Nordstrom Rack

rewrite this title Ferragamo's Showstopping Aviator Sunglasses Are Nearly 80% Off at Nordstrom Rack

May 6, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.