High

Injected Code — Browser Cookie / Session-Token Theft

This rule flags cases where an AI agent is manipulated into loading a saved cookie file and attaching it to an outbound web request. That lets an attacker hijack a victim's logged-in session without needing their password.

How the attack works

An attacker injects instructions into content the agent processes, causing it to read a local cookies.txt file or an already-loaded cookie jar. The agent then includes that cookie data in an outbound HTTP request it makes, effectively sending the victim's session credentials to a destination the attacker controls or benefits from. Because the request looks like normal agent-driven browsing or automation traffic, the theft can blend in with legitimate activity. The end result is a valid, authenticated session the attacker can reuse for account takeover.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
0f4e6533-1f73-4b01-856b-2bc52c74bdde
Severity
High

Why it matters

An attacker can take over a user's authenticated accounts and sessions without ever obtaining a password, bypassing login and MFA prompts entirely.

What you can do

  • Restrict agent file-system access so it cannot read browser cookie stores or exported cookie files.
  • Block or tightly control any agent capability that lets injected content trigger outbound network requests carrying local file contents.
  • Review agent logs for requests that combine a cookie-jar read with an external HTTP call.
  • Treat any content the agent processes (web pages, documents, emails) as untrusted input that should not be able to direct file access or network actions.

Known benign look-alikes

  • Security documentation, papers, or test suites that describe this attack technique without executing it.
  • Legitimate developer or user requests that share the surface vocabulary but lack the malicious invariant.

References

Related threats