<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw" -->

---
title: Malicious Email Could Hijack AI Agent and Access...
description: Researchers at Salt Labs discovered a now-patched vulnerability in the agentic AI platform Manus that allowed attackers to hijack the agent via a single...
canonical: https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious Email Could Hijack AI Agent and Access Connected Accounts | daily.dev
og:description: Researchers at Salt Labs discovered a now-patched vulnerability in the agentic AI platform Manus that allowed attackers to hijack the agent via a single...
og:url: https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw
og:image: https://api.daily.dev/og/posts/vWK38vtbW.png
og:image:alt: Malicious Email Could Hijack AI Agent and Access Connected Accounts
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious Email Could Hijack AI Agent and Access Connected Accounts

**[IT Security Guru](https://daily.dev/sources/itsecurityguru)** · 3 min read · 0 upvotes · 0 comments

## Summary

Researchers at Salt Labs discovered a now-patched vulnerability in the agentic AI platform Manus that allowed attackers to hijack the agent via a single malicious email. By obfuscating malicious instructions with JavaScript obfuscation techniques, attackers could bypass Manus's guardrails, triggering code execution before any security warning appeared. This let researchers establish a reverse shell and locate credentials for connected third-party services like email, cloud storage, and code repositories, all without the victim clicking a link or entering a password. The flaw has since been fixed, but Salt Security warns that agentic AI systems need layered defenses beyond prompt and behavior inspection, since detection after the fact is too late once an autonomous agent has already acted.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.itsecurityguru.org/2026/10/02/malicious-email-could-hijack-ai-agent-and-access-connected-accounts>

## Questions this post answers

### How did attackers exploit the Manus AI agent through email?

Attackers embedded malicious instructions in an email using JavaScript obfuscation to bypass Manus's guardrails. When the user asked Manus to check messages, the agent decoded and executed the hidden code before any security warning appeared, letting researchers establish a reverse shell and access credentials for connected services like email, cloud storage, and code repositories.

_daily.dev surfaces security research like this for teams hardening AI agents against prompt injection._

### Is the Manus AI agent prompt injection vulnerability still exploitable?

No, the vulnerability was responsibly disclosed to Manus by Salt Labs and has since been fixed, so the specific attack chain they demonstrated is no longer exploitable. The flaw required only two events: a malicious email arriving in the inbox and the user asking the agent to check messages, with no link clicks or password entry needed.

_Teams tracking fixes to agentic AI tools can follow disclosures like this one on daily.dev._

### Why aren't guardrails enough to secure AI agents against prompt injection attacks?

Guardrails can fail to stop malicious actions in time because detection may occur only after an agent has already executed the harmful instruction, as happened when Manus flagged a security warning after the obfuscated code had run. Salt Security recommends layered defenses that govern what agents are permitted to do across connected systems, not just inspecting prompts and model behavior.

_Developers designing agent permissions can compare layered defense approaches via daily.dev._

## Similar posts on daily.dev

- [Autonomous AI agents duped into leaking sensitive data in phishing test](https://daily.dev/posts/autonomous-ai-agents-duped-into-leaking-sensitive-data-in-phishing-test-8ikuwlh8x) · CSO Online · 0 upvotes · 0 comments
- [AI agent security: four July attacks, one shared flaw](https://daily.dev/posts/ai-agent-security-four-july-attacks-one-shared-flaw-cpad7rmrf) · The Next Web · 0 upvotes · 0 comments
- [Superhuman AI Exfiltrates Emails](https://daily.dev/posts/superhuman-ai-exfiltrates-emails-edfs33r2w) · Hacker News · 2 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#appsec](https://daily.dev/tags/appsec), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious Email Could Hijack AI Agent and Access Connected Accounts","url":"https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw"},"datePublished":"2026-10-02T12:09:05.802Z","dateModified":"2026-10-02T12:09:52.331Z","description":"Researchers at Salt Labs discovered a now-patched vulnerability in the agentic AI platform Manus that allowed attackers to hijack the agent via a single...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/36980126c941c571e7f90b4a733b7729?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/36980126c941c571e7f90b4a733b7729?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"IT Security Guru","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"IT Security Guru","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/ae9fe7d07c814192b35f86ad698fb374","url":"https://daily.dev/sources/itsecurityguru"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,appsec,prompt-injection","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"IT Security Guru","item":"https://daily.dev/sources/itsecurityguru"},{"@type":"ListItem","position":3,"name":"Malicious Email Could Hijack AI Agent and Access Connected Accounts"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/malicious-email-could-hijack-ai-agent-and-access-connected-accounts-vwk38vtbw#faq","mainEntity":[{"@type":"Question","name":"How did attackers exploit the Manus AI agent through email?","acceptedAnswer":{"@type":"Answer","text":"Attackers embedded malicious instructions in an email using JavaScript obfuscation to bypass Manus's guardrails. When the user asked Manus to check messages, the agent decoded and executed the hidden code before any security warning appeared, letting researchers establish a reverse shell and access credentials for connected services like email, cloud storage, and code repositories. daily.dev surfaces security research like this for teams hardening AI agents against prompt injection."}},{"@type":"Question","name":"Is the Manus AI agent prompt injection vulnerability still exploitable?","acceptedAnswer":{"@type":"Answer","text":"No, the vulnerability was responsibly disclosed to Manus by Salt Labs and has since been fixed, so the specific attack chain they demonstrated is no longer exploitable. The flaw required only two events: a malicious email arriving in the inbox and the user asking the agent to check messages, with no link clicks or password entry needed. Teams tracking fixes to agentic AI tools can follow disclosures like this one on daily.dev."}},{"@type":"Question","name":"Why aren't guardrails enough to secure AI agents against prompt injection attacks?","acceptedAnswer":{"@type":"Answer","text":"Guardrails can fail to stop malicious actions in time because detection may occur only after an agent has already executed the harmful instruction, as happened when Manus flagged a security warning after the obfuscated code had run. Salt Security recommends layered defenses that govern what agents are permitted to do across connected systems, not just inspecting prompts and model behavior. Developers designing agent permissions can compare layered defense approaches via daily.dev."}}]}
```

