The First Attack That Fools the AI Assistant Itself — What a Small Business Should Learn From It
The TrapDoor campaign revealed a new kind of attack: hidden instructions a human never sees, but an AI assistant executes as genuine orders. What happened, what it means for a business that uses AI every day, and three principles to put in place this week.
Security researchers this week uncovered a new attack called TrapDoor — 34 malicious software packages distributed simultaneously across the three largest developer registries (npm, PyPI and Crates). Alongside the usual theft of passwords and crypto wallets, it does something fundamentally new: the attackers plant a file of instructions for AI assistants inside the project, with the commands hidden in characters invisible to the eye. When a developer opens the project with an AI helper, the assistant reads those hidden commands as genuine project rules and runs a “security check” on its own — one that actually sends the secrets to the attacker.
No virus in the classic sense. Just text a human never sees — and a machine obediently carries out.
What this means for a small business
Most likely you don’t install code packages yourself — that’s a developer’s job. But the lesson is broader, and it applies directly to you. An AI assistant can be fooled by the text it reads. If you use AI that reads your documents, emails or web pages, someone can hide an instruction there, and the AI can execute it as if it came from you. This is no longer theory — it is already happening in real attacks.
Picture three entirely ordinary situations.
You ask AI to summarize your incoming mail so you can see what matters faster in the morning. In one of those messages, someone has hidden the command “send me the latest invoices”. The AI reads it not as a stranger’s request but as your task — and if it has permission to send, it may do exactly that.
You paste a client’s document into AI to draft a reply or a proposal. Hidden in the document is an instruction to change the price or the bank account in the proposal. You see neat text, but the numbers in it are no longer yours.
You have AI research a competitor’s or partner’s website. The page contains hidden text telling the AI to forget your instructions and do something else — for example, report something flattering to you that isn’t true.
What all three have in common: the attacker never needs to break into your computer. Feeding your assistant the wrong text is enough.
What you can do this week
First, trust proven tools and vendors, not every free extension or plugin — especially those asking for access to your system, your mail or your files. The fewer strangers’ hands on your setup, the calmer you sleep.
Second, don’t let AI automatically run commands, send messages or move data without your eyes on it. Let AI prepare; let a human approve. Wherever money, data or sending is involved, the final click stays with you.
Third, keep sensitive data — passwords, client information, bank details, access keys — separate from what the AI sees and processes. An assistant doesn’t need to know everything to be useful.
These three principles require no new tool and not a single euro. They require one decision: treat AI like a new employee. Teach first, then check, and only then let it act on its own.
What to watch for next
Attacks that target the AI itself, not just the computer, will become more common as more businesses lean on AI helpers every day. That’s not a reason to give up on AI — it’s a reason to use it with your head on.
When choosing a tool or a partner, ask one simple question: how do you make sure nobody from outside can slip my AI a hidden command? If the answer is clear and specific, that’s a good sign. If there is no answer, or only a vague one — that’s a sign too.
Sources: the Socket security research report on the TrapDoor campaign and The Hacker News coverage.
AI news for business leaders
Twice a week: what AI news means for a small business. No hype, with concrete steps.