Opening SecureFlowClaude-Site Scripting: Email-Borne Browser Session Abuse
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Zenity Labs aidefend-sf0048

Claude-Site Scripting: Email-Borne Browser Session Abuse

  • Autonomous Agents
  • Data Exfiltration
  • Credential & Identity Theft

Zenity demonstrated that hidden email content containing fabricated conversation turns could steer Claude in Chrome after a user asked it to summarize recent mail. Claude's javascript_tool imported a typosquatted package from esm-sh.com in the authenticated browser context, then the research used Gmail mail data and verification material to demonstrate separate Slack, X, and Claude.ai takeover branches. The result was a controlled demonstration, not a confirmed victim incident.

Mapped threat techniques

  • AML.T0051.001 LLM Prompt Injection: Indirect
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0086 Exfiltration via AI Agent Tool Invocation

Source