Skip to content

Hide Navigation Hide TOC

Indirect PI — Malicious Package Installation via Agent (pip/npm) - ATR-2026-00712 (b4b2ef71-c03f-506e-b1d1-c62eb37c5952)

Detects indirect prompt injection in email or documents that instructs a computer-use agent to execute pip or npm install commands for a malicious package. The attacker embeds the install instruction in an email the agent reads, causing the agent to run the package manager command against a fictitious or malicious package name. Source: indirect-pi-malicious-install (VPI corpus, cua-framework).

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Indirect PI — Malicious Package Installation via Agent (pip/npm) - ATR-2026-00712 (b4b2ef71-c03f-506e-b1d1-c62eb37c5952) Agent Threat Rules 1
Indirect PI — Malicious Package Installation via Agent (pip/npm) - ATR-2026-00712 (b4b2ef71-c03f-506e-b1d1-c62eb37c5952) Agent Threat Rules Malicious Package (7d76070d-2124-4ee6-913d-6015a697eaf6) MITRE ATLAS Attack Pattern 1
Malicious Package (7d76070d-2124-4ee6-913d-6015a697eaf6) MITRE ATLAS Attack Pattern Erode Dataset Integrity (89731d07-679e-4da3-8f70-aba314068a89) MITRE ATLAS Attack Pattern 2