Malicious npm and PyPI packages use prompt injection to bypass AI security scanners (opens in new tab)
A new wave of malicious packages on the npm and PyPI repositories is employing "indirect prompt injection" to disrupt AI-assisted malware analysis. Researchers identified that the Hades campaign and specific packages like shai_hulululud embed large blocks of deceptive text within non-executable code comments. This technique targets LLM-based triage pipelines by including forbidden topics or repetitive "token flooding" designed to trigger safety refusals or system timeouts. <a href="
Read the original article