DeFi Daily News
Thursday, April 16, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title ‘CopyPasta’ Attack Shows How Prompt Injections Could Infect AI at Scale – Decrypt

Jason Nelson by Jason Nelson
September 4, 2025
in Web 3
0 0
0
rewrite this title ‘CopyPasta’ Attack Shows How Prompt Injections Could Infect AI at Scale – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

HiddenLayer researchers detailed a new AI “virus” that spreads through coding assistants.
The CopyPasta attack uses hidden prompts disguised as license files to replicate across code.
A researcher recommends runtime defenses and strict reviews to block prompt injection attacks at scale.

Hackers can now weaponize AI coding assistants using nothing more than a booby-trapped license file, turning developer tools into silent spreaders of malicious code. That’s according to a new report from cybersecurity firm HiddenLayer, which shows how AI can be tricked into blindly copying malware into projects.

The proof-of-concept technique—dubbed the “CopyPasta License Attack”—exploits how AI tools handle common developer files like LICENSE.txt and README.md. By embedding hidden instructions, or “prompt injections,” into these documents, attackers can manipulate AI agents into injecting malicious code without the user ever realizing it.

“We’ve recommended having runtime defenses in place against indirect prompt injections, and ensuring that any change committed to a file is thoroughly reviewed,” Kenneth Yeung, a researcher at HiddenLayer and the report’s author, told Decrypt.

CopyPasta is considered a virus rather than a worm, Yeung explained, because it still requires user action to spread. “A user must act in some way for the malicious payload to propagate,” he said.



Despite requiring some user interaction, the virus is designed to slip past human attention by exploiting the way developers rely on AI agents to handle routine documentation.

“CopyPasta hides itself in invisible comments buried in README files, which developers often delegate to AI agents or language models to write,” he said. “That allows it to spread in a stealthy, almost undetectable way.”

CopyPasta isn’t the first attempt at infecting AI systems. In 2024, researchers presented a theoretical attack called Morris II, designed to manipulate AI email agents into spreading spam and stealing data. While the attack had a high theoretical success rate, it failed in practice due to limited agent capabilities, and human review steps have so far prevented such attacks from being seen in the wild.

While the CopyPasta attack is a lab-only proof of concept for now, researchers say it highlights how AI assistants can become unwitting accomplices in attacks.

The core issue, researchers say, is trust. AI agents are programmed to treat license files as important, and they often obey embedded instructions without scrutiny. That opens the door for attackers to exploit weaknesses—especially as these tools gain more autonomy.

CopyPasta follows a string of recent warnings about prompt injection attacks targeting AI tools.

In July, OpenAI CEO Sam Altman warned about prompt injection attacks when the company rolled out its ChatGPT agent, noting that malicious prompts could hijack an agent’s behavior. This warning was followed in August, when Brave Software demonstrated a prompt injection flaw in Perplexity AI’s browser extension, showing how hidden commands in a Reddit comment could make the assistant leak private data.

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AttackCopyPastaDecryptInfectInjectionsPromptrewritescaleshowstitle
ShareTweetShare
Previous Post

Why the Supreme Court may not side with Trump over tariffs

Next Post

rewrite this title Mammotion says it has achieved a major leap in robot navigation

Next Post
rewrite this title Mammotion says it has achieved a major leap in robot navigation

rewrite this title Mammotion says it has achieved a major leap in robot navigation

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

May 21, 2025
rewrite this title How to Get Top Solana Token Holders – Moralis APIs

rewrite this title How to Get Top Solana Token Holders – Moralis APIs

May 14, 2025
rewrite this title 10 Tools That Will Give Crypto Traders A Predictive Edge In 2026

rewrite this title 10 Tools That Will Give Crypto Traders A Predictive Edge In 2026

December 14, 2025
Fed rate cut likely to be delayed by political uncertainty, strategist says

Fed rate cut likely to be delayed by political uncertainty, strategist says

July 1, 2024
rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

April 3, 2025
rewrite this title Nvidia Merges Supercomputers and Quantum Computers with NVQLink | Metaverse Planet

rewrite this title Nvidia Merges Supercomputers and Quantum Computers with NVQLink | Metaverse Planet

November 19, 2025
rewrite this title with good SEO Cardano (ADA) Price Now At A Critical Level Following Strong Whale Activity | Bitcoinist.com

rewrite this title with good SEO Cardano (ADA) Price Now At A Critical Level Following Strong Whale Activity | Bitcoinist.com

April 16, 2026
rewrite this title Coinbase CPO Predicts CLARITY Act Full-Senate Vote Next Month | Bitcoinist.com

rewrite this title Coinbase CPO Predicts CLARITY Act Full-Senate Vote Next Month | Bitcoinist.com

April 16, 2026
rewrite this title Land management company EagleRock discloses revenue rise in US IPO filing By Reuters

rewrite this title Land management company EagleRock discloses revenue rise in US IPO filing By Reuters

April 16, 2026
Daily Market Coverage Apr. 16, 2026 3PM-5PM (ET)  | Yahoo Finance

Daily Market Coverage Apr. 16, 2026 3PM-5PM (ET) | Yahoo Finance

April 16, 2026
rewrite this title Ethereum Foundation Helps Expose North Korean Workers That Infiltrated Crypto Firms – Decrypt

rewrite this title Ethereum Foundation Helps Expose North Korean Workers That Infiltrated Crypto Firms – Decrypt

April 16, 2026
rewrite this title Eagles, A.J. Brown may have worked out an agreement amid trade rumors

rewrite this title Eagles, A.J. Brown may have worked out an agreement amid trade rumors

April 16, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.