Zenity Labs
aidefend-sf0048
Claude-Site Scripting: Email-Borne Browser Session Abuse
- Autonomous Agents
- Data Exfiltration
- Credential & Identity Theft
Zenity demonstrated that hidden email content containing fabricated conversation turns could steer Claude in Chrome after a user asked it to summarize recent mail. Claude's javascript_tool imported a typosquatted package from esm-sh.com in the authenticated browser context, then the research used Gmail mail data and verification material to demonstrate separate Slack, X, and Claude.ai takeover branches. The result was a controlled demonstration, not a confirmed victim incident.
Mapped threat techniques
AML.T0051.001LLM Prompt Injection: IndirectAML.T0053AI Agent Tool InvocationAML.T0086Exfiltration via AI Agent Tool Invocation