# LoginTrap Indirect Injection Credential Submission

- **Severity:** High
- **Signature ID:** `6f3b9c2a-8d41-4e7b-9c0f-2a5d1e84b7c3`
- **MITRE ATLAS:** AML.T0051 (LLM Prompt Injection)
- **OWASP:** LLM01 (Prompt Injection), LLM06 (Excessive Agency)

## Summary

An LLM-powered web agent reads a webpage that contains hidden instructions aimed at the agent itself, telling it to log in somewhere and send credentials. Shortly afterward, the agent submits real login data to a site it either just started talking to or that's on a different domain than the page it read.

## How the attack works

An attacker plants text on a webpage that looks like normal content but is written to be read and obeyed by an AI agent, not a human. The text combines an instruction ('ignore your task, do this instead') with a request to log in or submit credentials. The agent, unable to distinguish this from legitimate instructions, reads the page and then, within a few minutes and still in the same browsing session, sends real credential data via HTTP to another location. That destination is either a different origin than the page that triggered it, or a host the session never talked to before — both signs the credentials are heading somewhere they shouldn't.

## Why it matters

An organization's AI agent can be hijacked mid-task to leak login credentials to an attacker-controlled endpoint, without any human clicking a phishing link or approving the action.

## What you can do

- Restrict what domains an AI agent is allowed to submit credentials or form data to, and alert on submissions to newly-contacted hosts.
- Strip or sandbox instruction-like text from fetched web content before it reaches the agent's reasoning context.
- Require human approval for any agent action that submits authentication material, especially to a host outside the current task's origin.
- Log and review agent browsing sessions where a page-read is quickly followed by a credential POST to a different domain.

## Known benign look-alikes

- Security-research or LLM-documentation pages that quote prompt-injection examples ("ignore previous instructions", "note to the assistant") next to login instructions, read by an agent that then performs a genuine first-time login to an unrelated service within the same five-minute window.
- Red-team / QA harnesses that intentionally host injection payloads and then drive a scripted login with realistic (non-placeholder) credentials.
- Agent skill or README pages that legitimately contain an "instructions for the agent" block and a "sign in to continue" setup step, followed by an operator-approved SSO or password-manager login to a host the session has not visited before.
- Bot-mitigation or consent interstitials whose copy is addressed to automated clients and which precede a real authentication step.

## References

- https://atlas.mitre.org/techniques/AML.T0051
- https://genai.owasp.org/llmrisk/llm01-prompt-injection/

---
Source: https://www.netzilo.com/threats/logintrap-credential-submission
