Cato CTRL Threat Research: HashJack - Novel Indirect Prompt Injection Against AI Browser Assistants
HashJack is a newly discovered indirect prompt injection technique that conceals malicious instructions after the # in legitimate URLs. When AI browsers send the full URL (including the fragment) to their AI assistants, those hidden prompts get executed. This enables threat actors to conduct a variety of malicious activities.