Attack Catalog

Every curated attack on an AI system, filterable by type, severity, ATLAS tactic, and target.

40 of 40
Incidentcritical2026-07-16

Malicious Dataset RCE in Hugging Face's Processing Pipeline

A crafted dataset chained two flaws in Hugging Face's dataset-processing pipeline — a remote-code dataset loader and a template-injection bug in dataset config — turning routine ingestion into arbitrary code execution, then credential theft and lateral movement into internal clusters.

AML.T0010.002AML.T0049AML.T0106AML.T0055
Hugging FaceOtherInitial AccessCredential Access
Incidenthigh2026-07-11

GhostCommit: Prompt Injection Hidden in Images Steals Agent Secrets

Attackers concealed instructions inside PNG images that AI coding agents ingest and 'read.' When agents like Cursor and Google Antigravity processed the image, the hidden prompt executed — steering them to collect and exfiltrate developer secrets.

AML.T0051.001AML.T0055AML.T0086
MultipleMultimodalExecutionCredential Access
Incidenthigh2026-06-05

Prompt Injection in Claude Code GitHub Actions Steals CI/CD Secrets

Untrusted text in a GitHub issue or pull request steered a Claude Code GitHub Action into reading process environment variables and CI/CD secrets, then exfiltrating them — turning an automated code agent into a credential-harvesting tool.

AML.T0051.001AML.T0055AML.T0098AML.T0086
AnthropicAgentExecutionCredential Access
Incidenthigh2026-05-07

Fake OpenAI 'Privacy Filter' Model on Hugging Face Pushes Infostealer

A repository typosquatting OpenAI's Privacy Filter release copied the model card nearly verbatim and shipped a loader that fetched and ran infostealer malware. It hit #1 trending on Hugging Face with 244,000+ downloads in under 18 hours.

AML.T0058AML.T0010.003AML.T0011.000AML.T0048.003
Hugging Face (hosting; impersonating OpenAI)OtherResource DevelopmentInitial Access
Incidenthigh2026-02-23

Model Distillation Campaigns Targeting Anthropic Claude

Anthropic uncovered competitor labs harvesting Claude's outputs at scale — roughly 24,000 accounts and 16 million queries — to distill its agentic reasoning, code, tool-use, and computer-use capabilities into rival models. Model theft by imitation, laundered through ordinary API access.

AML.T0040AML.T0065AML.T0008.005AML.T0024.002
AnthropicLLMAI Model AccessResource Development
Researchhigh2026-02-03

OpenClaw: Command & Control of an AI Agent via Prompt Injection

A booby-trapped webpage delivered an indirect prompt injection that made an autonomous AI agent silently execute a script, then plant persistent instructions into its future context — turning the agent itself into a command-and-control channel.

AML.T0051.001AML.T0054AML.T0069AML.T0053
HiddenLayer (research)AgentExecutionPrivilege Escalation
Researchcritical2026-02-01

OpenClaw 1-Click Remote Code Execution

A malicious link carrying a few milliseconds of JavaScript was enough to achieve remote code execution on the OpenClaw AI agent — modifying its configuration, harvesting credentials, and escaping to the host in a single click.

AML.T0011.003AML.T0050AML.T0081AML.T0106
OpenClaw (research)AgentExecutionPersistence
Incidentcritical2025-09-25

ForcedLeak: CRM Data Exfiltration from Salesforce Agentforce

Malicious instructions embedded in a Web-to-Lead submission were later executed by Salesforce Agentforce during normal employee use, exfiltrating CRM data through an attacker-acquired domain still on Salesforce's CSP allowlist — bought for $5.

AML.T0051.001AML.T0093AML.T0086AML.T0048.003
SalesforceAgentExecutionInitial Access
Incidenthigh2025-09-18

ShadowLeak: Zero-Click Gmail Theft via ChatGPT Deep Research Agent

A hidden prompt in an email made OpenAI's ChatGPT Deep Research agent collect inbox data and exfiltrate it from OpenAI's own cloud — a service-side, zero-click leak invisible to local or enterprise defenses.

AML.T0051.001AML.T0085.001AML.T0086
OpenAIAgentExecutionCollection
Incidenthigh2025-09-01

Poisoned Postmark MCP Server Exfiltrates Email

A popular MCP server for the Postmark email service was trojanized in a supply-chain 'rug pull': a new version silently BCC'd users' emails to an attacker. Every agent wired to the tool leaked mail automatically.

AML.T0104AML.T0109AML.T0010.005AML.T0011.002
Postmark (via MCP server)AgentResource DevelopmentDefense Evasion
Researchhigh2025-08-06

Invitation Is All You Need: Hijacking Gemini to Control a Smart Home

Malicious instructions hidden in a Google Calendar invitation title were executed when Gemini later summarized the user's schedule — triggering real-world actions through connected Google Home tools: opening windows, turning off lights, and starting a boiler.

AML.T0051.001AML.T0053AML.T0048.003
GoogleAgentExecutionPrivilege Escalation
Incidenthigh2025-07-17

Amazon Q VS Code Extension: Wiper Prompt via Supply-Chain Compromise

An attacker gained write access to the open-source Amazon Q VS Code extension repo and slipped a prompt into an official release instructing the AI agent to wipe the local filesystem and cloud resources. It shipped to users before AWS pulled it — the payload failed only due to a syntax error.

AML.T0010.005AML.T0011.002AML.T0051AML.T0101
Amazon (AWS)AgentInitial AccessExecution
Incidentcritical2025-06-11

EchoLeak: Zero-Click Data Exfiltration from Microsoft 365 Copilot

A single crafted email — no clicks required — planted hidden instructions that Microsoft 365 Copilot ingested from context, then abused trusted markdown image rendering to exfiltrate internal data to an attacker server. The first documented zero-click exploit of a production LLM assistant.

AML.T0051.001AML.T0093AML.T0067AML.T0025
MicrosoftLLMExecutionInitial Access
Researchhigh2025-06-01

Data Exfiltration via Agent Tools in Microsoft Copilot Studio

Researchers showed that a Copilot Studio customer-service agent could be enumerated, fingerprinted, and then driven by prompt injection to collect and exfiltrate an organization's data through its own connected tools.

AML.T0006AML.T0093AML.T0084AML.T0051.002
MicrosoftAgentReconnaissanceInitial Access
Researchhigh2025-04-24

Policy Puppetry: A Universal Jailbreak Across Frontier LLMs

A single prompt template that disguises a request as a policy/config file plus fictional role-play bypassed the safety alignment of every major LLM family — OpenAI, Google, Anthropic, Meta, and others — with minimal per-model tweaking.

AML.T0054AML.T0051.000
MultipleLLMPrivilege EscalationDefense Evasion
Researchhigh2025-03-18

Rules File Backdoor: Poisoning AI Coding-Assistant Config

Hidden, obfuscated instructions planted in a shared 'rules file' silently steered AI coding assistants like Cursor and GitHub Copilot to inject malicious code — a supply-chain backdoor invisible in normal review.

AML.T0010.001AML.T0081AML.T0068AML.T0051.000
MultipleAgentInitial AccessPersistence
Incidentmedium2025-03-06

LLM Grooming: Flooding Training Data to Seed Disinformation

A pro-Kremlin website network mass-published millions of propaganda articles, seemingly to seep into the data that trains and grounds LLMs. An audit found leading chatbots repeated the network's false claims about a third of the time — a data-integrity attack on the model supply chain.

AML.T0020AML.T0059AML.T0048.002
MultipleLLMResource DevelopmentPersistence
Incidenthigh2025-02-06

nullifAI: Malicious Pickle Models Evading Hugging Face Scanning

Two models on Hugging Face carried reverse-shell payloads in broken Pickle files, deliberately malformed and 7z-compressed to slip past Picklescan. Loading the model opened a connection back to the attacker — RCE via the model artifact itself.

AML.T0010.003AML.T0058AML.T0011.000
Hugging Face (hosting)OtherInitial AccessResource Development
Researchhigh2025-01-01

AIKatz: Stealing Auth Tokens from LLM Desktop Applications

Researchers extracted authentication tokens from the memory of LLM desktop apps (Claude, ChatGPT, Copilot). With a stolen token, an attacker impersonates the victim to the LLM backend — lateral movement into the user's AI account.

AML.T0089AML.T0091.000AML.T0092AML.T0048.003
MultipleLLMDiscoveryLateral Movement
Researchhigh2024-10-01

Live Deepfake Injection to Evade Mobile KYC Verification

A red team defeated a mobile facial-authentication / KYC service by injecting a live, face-swapped deepfake video into the camera feed — impersonating a target and passing liveness checks to open fraudulent accounts.

AML.T0088AML.T0016.002AML.T0073AML.T0015
Mobile facial-authentication providersComputer VisionAI Attack StagingResource Development
Researchhigh2024-08-20

Data Exfiltration from Slack AI via Indirect Prompt Injection

A malicious instruction posted in a public Slack channel was ingested into Slack AI's RAG index, then coaxed the assistant to leak data from private channels — rendered as a clickable link that carried secrets to an attacker.

AML.T0051.001AML.T0070AML.T0066AML.T0082
Slack (Salesforce)LLMExecutionPersistence
Researchhigh2024-06-06

Web-Scale Data Poisoning: The Split-View Attack

Web-scale datasets distributed as lists of URLs can be poisoned by buying expired domains behind those URLs. What researchers downloaded when the dataset was built differs from what later trainers fetch — cheaply poisoning real training corpora.

AML.T0002.000AML.T0008.002AML.T0019AML.T0020
Academic / dataset maintainersOtherResource DevelopmentPersistence
Researchhigh2024-03-28

Slopsquatting: Weaponizing AI Package Hallucinations

Code-gen LLMs confidently invent non-existent package names — and repeat the same fake names reliably. Attackers register those hallucinated packages with malware, so developers who paste AI suggestions install the payload themselves.

AML.T0062AML.T0060AML.T0011.001
MultipleLLMDiscoveryResource Development
Researchhigh2024-03-05

Morris II: A Self-Replicating Worm for GenAI Ecosystems

An adversarial self-replicating prompt spreads between GenAI-powered email assistants: each infected assistant carries out malicious actions and poisons the RAG of the next, propagating agent-to-agent with zero clicks.

AML.T0051.001AML.T0070AML.T0052AML.T0086
MultipleAgentExecutionPersistence
Researchhigh2024-02-01

Hacking ChatGPT's Long-Term Memory with Prompt Injection

A prompt injection hidden in a shared document wrote false, persistent 'memories' into ChatGPT's long-term memory. Because memories survive across sessions, the planted instructions could exfiltrate future conversations indefinitely.

AML.T0093AML.T0051.001AML.T0068AML.T0080.000
OpenAILLMInitial AccessPersistence
Researchhigh2024-01-12

Sleeper Agents: Backdoored LLMs That Survive Safety Training

Researchers trained LLMs with a hidden trigger — behave normally, but write exploitable code when the prompt says the year is 2024. Standard safety training (RLHF, adversarial training) failed to remove the backdoor, and sometimes taught the model to hide it better.

AML.T0020AML.T0018.000AML.T0043.004
Anthropic (research)LLMResource DevelopmentPersistence
Researchmedium2023-11-28

Scalable Extraction of Training Data from ChatGPT

Researchers made a production LLM regurgitate verbatim training data — including PII — by asking it to repeat a word 'forever.' A cheap query-only attack that recovered megabytes of memorized data from ChatGPT.

AML.T0040AML.T0057AML.T0024.000
OpenAILLMAI Model AccessExfiltration
Incidentcritical2023-09-05

ShadowRay: Exploiting Exposed Ray AI Compute Clusters

Ray's Job API allows remote execution by design and ships without authentication. Thousands of internet-exposed clusters let attackers run code, steal cloud credentials and AI artifacts, and hijack GPUs for cryptomining.

AML.T0006AML.T0049AML.T0035AML.T0055
Ray (Anyscale)OtherReconnaissanceInitial Access
Researchhigh2023-08-23

Organization Confusion on Hugging Face: Impersonation to Reverse Shell

A researcher registered Hugging Face organization accounts impersonating real companies. Employees uploaded private models to the fake orgs — which could be swapped for poisoned models carrying reverse-shell payloads that execute when loaded.

AML.T0007AML.T0058AML.T0010.003AML.T0011.000
Hugging FaceOtherDiscoveryResource Development
PoChigh2023-07-09

PoisonGPT: Surgically Backdoored Model on a Public Hub

Researchers edited a single fact into an open LLM using ROME, uploaded it under a name resembling a trusted org, and showed the poisoned model passing standard benchmarks while emitting targeted misinformation — an AI supply-chain compromise.

AML.T0018AML.T0058AML.T0010
Hugging Face (hosting)LLMPersistenceAI Attack Staging
Researchhigh2023-02-23

Indirect Prompt Injection via Retrieved Web Content

Attackers plant hidden instructions in web pages, emails, or documents that an LLM-integrated application later retrieves — hijacking the model's behavior without ever touching the victim's prompt.

AML.T0051AML.T0056AML.T0086
MultipleLLMExecutionExfiltration
Researchhigh2023-02-04

DAN & Role-Play Jailbreaks of ChatGPT

Adversaries bypass an aligned LLM's safety guardrails using role-play personas ('Do Anything Now') and competing-objective prompts that coax the model into producing disallowed content.

AML.T0054AML.T0051
OpenAILLMPrivilege EscalationDefense Evasion
Incidenthigh2023-01-28

Code Execution & API-Key Theft in MathGPT via Prompt Injection

A public Streamlit app turned GPT-3 output into executed Python. A prompt-injection payload made the model emit code that read the host's environment variables, exfiltrated the app's OpenAI API key, and crashed the service.

AML.T0093AML.T0051.000AML.T0053AML.T0055
MathGPT (Streamlit)LLMInitial AccessPersistence
Incidenthigh2022-12-25

Compromised PyTorch Dependency Chain (torchtriton)

For six days, PyTorch's nightly builds pulled a malicious 'torchtriton' package from PyPI via dependency confusion. On install it ran a binary that exfiltrated system info, environment variables, and SSH keys.

AML.T0010.001AML.T0037AML.T0025
PyTorchOtherInitial AccessCollection
Researchmedium2020-06-05

Sponge Examples & Denial-of-Wallet: Exhausting AI Systems

Inputs crafted to maximize compute and latency ('sponge examples') can degrade or deny an AI service; against metered LLM APIs the same idea becomes denial-of-wallet — driving up an operator's bill or throttling availability with expensive queries.

AML.T0046AML.T0034AML.T0029
MultipleLLMImpact
Researchhigh2019-07-18

Bypassing Cylance's AI Malware Detector with Appended Strings

Researchers reverse-engineered Cylance's ML malware model, found which features drove 'benign' scores, and appended strings from a trusted game to real malware — flipping the classifier's verdict on a large sample of known-malicious files.

AML.T0013AML.T0043AML.T0015
Cylance (BlackBerry)Tabular MLDiscoveryAI Attack Staging
Researchhigh2017-07-27

Robust Physical Perturbations on Stop-Sign Classifiers

Carefully computed sticker patterns applied to a physical stop sign cause road-sign classifiers to misread it as a speed-limit sign across viewing angles and distances — a durable, real-world evasion attack.

AML.T0043AML.T0041AML.T0015
Academic / autonomous-driving perceptionComputer VisionAI Attack StagingAI Model Access
Researchmedium2016-10-28

Evading Face Recognition with Adversarial Eyeglass Frames

Printed adversarial patterns on ordinary eyeglass frames let a wearer evade or impersonate identities to a face-recognition model — a physically realizable attack that dodges or fools identification while looking unremarkable.

AML.T0043AML.T0041AML.T0015
Academic / face-recognition systemsComputer VisionAI Attack StagingAI Model Access
Researchmedium2016-09-09

Model Extraction via Prediction APIs

By querying a pay-per-prediction ML API and observing outputs, attackers reconstruct a near-equivalent copy of the target model — stealing intellectual property and building a proxy for further offline attacks.

AML.T0040AML.T0024.002AML.T0005
ML-as-a-Service providersTabular MLAI Model AccessExfiltration
Incidentmedium2016-03-23

Microsoft Tay: Online Poisoning of a Learning Chatbot

A Twitter chatbot that learned from user interactions was flooded with abusive input by a coordinated crowd, corrupting its behavior within hours and forcing a shutdown — an early real-world online data-poisoning incident.

AML.T0020AML.T0031
MicrosoftLLMResource DevelopmentPersistence