← All hunts medium TLP:CLEAR

Exploitation of AI-Generated Vibe-Coded Applications

An attacker is exploiting vulnerabilities in AI-generated applications—such as missing input validation or hardcoded secrets—to gain initial access, brute-force credentials, or execute code from user-writable directories.

Based on research by ESET Research 2026-09-29 12 steps · 5 queries T1110 T1190

Brief

Why this hunt? 1000

In the article "Is that vibe coded app safe? 5 checks before you download" (https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/), ESET researchers explore the risks of applications generated by AI. This trend, known as "vibe coding," enables users to build functional software by simply describing requirements. While this accelerates development, it frequently results in code that misses critical security controls. These applications often enter the environment without formal security review or static analysis.

The primary risk involves the lack of production-grade hardening. Vibe-coded apps are often prototypes that "just work." They frequently contain vulnerabilities like hardcoded API keys, missing rate limiting on login forms, and a complete lack of input validation. Because these apps are often hosted on developer workstations or internal servers, they provide a path for attackers to gain a foothold in sensitive network segments. This hunt identifies these applications and determines if anyone is attempting to exploit them.

How the hunt flows

The first phase scopes the environment to identify where these applications exist. The first query searches the software inventory for packages and vendors linked to popular AI-generation platforms. It looks for names like Lovable, Replit, Bolt, and Cursor. This step allows the analyst to focus subsequent, more resource-intensive queries on the specific subset of hosts running these tools.

Once the analyst has a list of target hosts, the hunt moves into a parallel evidence-gathering phase. One branch queries vulnerability management data for findings on these hosts related to validation or encryption. This helps identify which AI-generated tools have known weaknesses. The second branch examines HTTP activity. It looks for traffic targeting common AI backend endpoints, such as URI paths used for prompt generation or chat interfaces. These paths are the primary targets for prompt injection attacks.

The final phase looks for signs of impact. The hunt queries for authentication spikes that indicate brute-force attempts against the application's login interfaces. Since vibe-coded apps rarely implement rate limiting, they are vulnerable to simple password guessing. Simultaneously, the hunt looks for rare process execution on these hosts. It targets processes launching from user-writable directories, such as AppData or /tmp, which might indicate that an attacker successfully exploited a file-upload or code-execution vulnerability. An analyst then evaluates the full chain to confirm an intrusion.

What the hunt cannot see

This hunt has two primary blind spots. First, standard HTTP activity logs typically do not capture the request body. If an attacker places a malicious prompt injection payload inside a POST request body rather than the URL, this hunt sees the connection but cannot see the intent. Second, the hunt depends on existing software signatures and vulnerability findings. Because vibe-coding allows for bespoke applications, some tools might use unique names or contain zero-day vulnerabilities that scanners have not yet indexed.

Steps

  1. Scope hosts with AI-generated apps

    Query · scoping

    Identify hosts where software from AI-generation platforms is installed to narrow the hunt to relevant assets.

    reads hb_software_inventorysql
    SELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'

    What a hit looks like. A list of hosts and software packages. Silence means no known vibe-coding platforms were found in the software inventory.

  2. Vulnerability findings for insecure code

    Query · enrichment

    Narrow the search to findings related to input validation or encryption on hosts already identified as having AI-generated apps.

    reads hb_vulnerability_findingsql
    SELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')

    What a hit looks like. Findings indicating insecure development practices on target hosts. Silence means no validation-related CVEs are currently open on those assets.

  3. HTTP traffic to AI endpoints

    Query · triage

    Find traffic targeting AI-related URI paths where prompt injection often occurs, indicating possible backend exploitation attempts.

    reads hb_http_activitysql
    SELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Requests to AI-specific backend paths. Silence means no tracked endpoints were accessed during the lookback window.

  4. Early stage exposure analysis

    Agent triage

    Determine if any host shows a combination of AI apps and either known vulnerabilities or suspicious traffic patterns before looking for impact.

  5. Brute force against unprotected logins

    Query · detection candidate

    Detect failed login spikes scoped to the identified AI-app hosts, where rate-limiting is likely missing.

    reads hb_auth_signinsql
    SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}

    What a hit looks like. Hosts or IPs showing excessive failed logins. Silence indicates no password guessing was observed on these specific hosts.

  6. Rare execution from app directories

    Query · baseline

    Find rare processes launched from user-writable paths specifically on the hosts hosting AI apps.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A process launched from a user profile on a scoped host. Silence proves no rare processes launched from these paths in the current snapshot.

  7. Final impact assessment

    Agent triage

    Consolidate the early-stage findings with follow-on brute force or suspicious process activity to confirm an intrusion chain.

  8. Route on final verdict

    Decision

    Determine whether to contain the host based on the high-confidence agent verdict.

  9. Isolate host

    Response action

    Contain confirmed intrusion to prevent lateral movement or data exfiltration.

  10. Analyst validation

    Analyst task

    Review the agent's findings and verify the malicious activity.

  11. Close out

    Analyst task

    Finalize the hunt and record improvements.

Coverage

Scenario coverage

StageCoveredHow, or why not
Identification of Insecure AI Apps
T1190
Yes scope-vibe-apps, vuln-findings
Exploitation of Web Vulnerabilities
T1190
Yes http-injection
Brute Force Against Unprotected Logins
T1110
Yes signin-brute-force
Malicious App Execution Yes rare-process-execution

Blind spots

  • Needs hb_http_activity with request body capture. Attackers can hide malicious prompts in the HTTP request body which is not captured by standard proxy or server logs. It would answer Are prompt injection payloads hidden in POST bodies?.
  • Needs Source code scanning integration. Software inventory and vulnerability findings only see what is already known; new vibe-coded apps have bespoke flaws not yet indexed. It would answer Does the app contain hardcoded secrets not yet known to scanners?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
brute_force_limitnumber20Threshold for login failures from a single IP to indicate brute forcing.
injection_patternslist[string]/api/ai/chat, /api/generate, /v1/completions, /promptSpecific URI paths commonly used by AI-integrated backends that are targets for injection.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Hosts to narrow the follow-on search; the analyst should populate this from the scoping step results.
vibe_platformslist[string]lovable, replit, vibe, bolt.new, cursorKeywords or vendor names associated with AI-coding platforms.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple rule cannot link the presence of an AI-generated package to its
  specific unvalidated URI paths and a subsequent brute-force spike. This hunt pivots
  across inventory, vulnerabilities, HTTP, and auth logs using a phased flow to confirm
  a full attack chain.
blind_spots:
- id: no-http-body-telemetry
  question: Are prompt injection payloads hidden in POST bodies?
  requires: hb_http_activity with request body capture
  risk: Attackers can hide malicious prompts in the HTTP request body which is not
    captured by standard proxy or server logs.
  stage: exploit-vibe-coded-backend
- id: os-agnostic-vulnerabilities
  question: Does the app contain hardcoded secrets not yet known to scanners?
  requires: Source code scanning integration
  risk: Software inventory and vulnerability findings only see what is already known;
    new vibe-coded apps have bespoke flaws not yet indexed.
  stage: vulnerability-discovery
coverage:
- stage: vulnerability-discovery
  status: covered
  steps:
  - scope-vibe-apps
  - vuln-findings
- stage: exploit-vibe-coded-backend
  status: covered
  steps:
  - http-injection
- stage: brute-force-credential-access
  status: covered
  steps:
  - signin-brute-force
- stage: malicious-app-installation
  status: covered
  steps:
  - rare-process-execution
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: AI-generated applications are appearing in environments without formal
    security vetting, introducing risks like missing rate-limiting and input validation;
    finding these before they are exploited is a critical exposure check for modern
    developer environments.
  methodology: model-assisted
  trigger: intel-report
hypothesis: "An attacker is exploiting vulnerabilities in AI-generated applications\u2014\
  such as missing input validation or hardcoded secrets\u2014to gain initial access,\
  \ brute-force credentials, or execute code from user-writable directories."
labels:
- hunt
- attack.t1190
- attack.t1110
- credential access
- discovery
- execution
- initial access
name: Exploitation of AI-Generated Vibe-Coded Applications
parameters:
  brute_force_limit:
    default: '20'
    description: Threshold for login failures from a single IP to indicate brute forcing.
    type: number
  injection_patterns:
    default:
    - /api/ai/chat
    - /api/generate
    - /v1/completions
    - /prompt
    description: Specific URI paths commonly used by AI-integrated backends that are
      targets for injection.
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Hosts to narrow the follow-on search; the analyst should populate
      this from the scoping step results.
    type: list[host]
  vibe_platforms:
    default:
    - lovable
    - replit
    - vibe
    - bolt.new
    - cursor
    description: Keywords or vendor names associated with AI-coding platforms.
    from:
      kind: article
      observed: '2026-09-25'
      ref: eset-research
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on developer workstations and servers hosting internal prototypes.
  Narrow the lookback if the HTTP traffic volume is high.
references:
- name: Is that vibe coded app safe? 5 checks before you download
  url: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
related:
- hunt: hardcoded-secrets-in-scripts
  reason: Searching for secrets in file content requires hb_file_activity with data
    capture or hb_script_activity, which is a separate hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Identification of Insecure AI Apps
    observables:
    - vulnerabilities in Lovable-hosted apps
    - missing input validation
    - hardcoded API keys
    - weak encryption settings
    - public-by-default access controls
    slug: vulnerability-discovery
    tactic: discovery
    techniques:
    - T1190
  - name: Exploitation of Web Vulnerabilities
    observables:
    - malicious prompt injection
    - unauthorized web requests to application endpoints
    - manipulation of input fields due to missing validation
    - extraction of sensitive user data from backend databases
    slug: exploit-vibe-coded-backend
    tactic: initial-access
    techniques:
    - T1190
  - name: Brute Force Against Unprotected Logins
    observables:
    - repeated login failures without rate limiting
    - automated password guessing attempts
    - high volume of auth requests from single IP
    - leaked session tokens
    slug: brute-force-credential-access
    tactic: credential-access
    techniques:
    - T1110
  - name: Malicious App Execution
    observables:
    - unauthorized malware installation
    - suspicious process launches from app directories
    - apps requesting excessive camera or data permissions
    - factory reset indicators on Android devices
    slug: malicious-app-installation
    tactic: execution
  summary: AI-generated 'vibe coded' applications often lack fundamental security
    controls like rate limiting and input validation, exposing them to brute force
    and exploitation. This scenario covers the identification of these vulnerable
    applications and the subsequent credential access or exploitation attempts by
    malicious actors.
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Exploitation of AI-Generated Vibe-Coded Applications

Vibe coding allows rapid application development but often bypasses traditional security reviews, leading to critical flaws such as missing input validation and rate limiting. This hunt identifies the presence of apps from popular AI-coding platforms, detects early signs of web-based exploitation like prompt injection, and correlates these with follow-on credential access or suspicious host activity. By phasing the analysis, we distinguish between generic noise and targeted exploitation of insecurely built internal tools that lack production-grade security controls.

## scope-vibe-apps
<!-- Scope hosts with AI-generated apps -->
Identify hosts where software from AI-generation platforms is installed to narrow the hunt to relevant assets.

```sqlite target=endpoint role=scoping params=(vibe_platforms=vibe_platforms)
~~~yaml
expected: A list of hosts and software packages. Silence means no known vibe-coding
  platforms were found in the software inventory.
reads:
- device_hostname
- device_uid
- package_name
- vendor_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'
```

## early-stage-parallel
<!-- Gather early exploitation evidence -->
parallel:
- → vuln-findings
- → http-injection
join: → early-triage

## vuln-findings
<!-- Vulnerability findings for insecure code -->
Narrow the search to findings related to input validation or encryption on hosts already identified as having AI-generated apps.

```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts)
~~~yaml
expected: Findings indicating insecure development practices on target hosts. Silence
  means no validation-related CVEs are currently open on those assets.
reads:
- device_uid
- title
- severity
- affected_package_name
silence: evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')
```

## http-injection
<!-- HTTP traffic to AI endpoints -->
Find traffic targeting AI-related URI paths where prompt injection often occurs, indicating possible backend exploitation attempts.

```sqlite target=web role=triage params=(injection_patterns=injection_patterns, lookback_days=lookback_days)
~~~yaml
expected: Requests to AI-specific backend paths. Silence means no tracked endpoints
  were accessed during the lookback window.
reads:
- device_hostname
- src_endpoint_ip
- url_full
- http_method
- url_path
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-triage
<!-- Early stage exposure analysis -->
```agent target=hunter
cite: required
context:
- scope-vibe-apps
- vuln-findings
- http-injection
max_iterations: 4
objective: Determine if any host has a combination of AI apps and either known vulnerabilities
  or suspicious traffic patterns indicating a beachhead.
success_criteria: A per-host verdict on the likelihood of initial access attempts.
tools:
- endpoint
- identity
- web
```

## follow-on-parallel
<!-- Check for credential access and execution -->
parallel:
- → signin-brute-force
- → rare-process-execution
join: → impact-assessment

## signin-brute-force
<!-- Brute force against unprotected logins -->
Detect failed login spikes scoped to the identified AI-app hosts, where rate-limiting is likely missing.

```sqlite target=identity role=detection-candidate params=(lookback_days=lookback_days, brute_force_limit=brute_force_limit, scope_hosts=scope_hosts)
~~~yaml
expected: Hosts or IPs showing excessive failed logins. Silence indicates no password
  guessing was observed on these specific hosts.
reads:
- dst_endpoint_name
- src_endpoint_ip
- actor_user_name
- time
- activity_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}
```

## rare-process-execution
<!-- Rare execution from app directories -->
Find rare processes launched from user-writable paths specifically on the hosts hosting AI apps.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A process launched from a user profile on a scoped host. Silence proves
  no rare processes launched from these paths in the current snapshot.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 3
reads:
- device_hostname
- process_name
- process_path
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## impact-assessment
<!-- Final impact assessment -->
```agent target=hunter
cite: required
context:
- early-triage
- signin-brute-force
- rare-process-execution
max_iterations: 6
objective: Determine if an attacker transitioned from exploiting a vulnerable AI app
  to gaining credential access or executing code, using context from the early triage.
success_criteria: A final verdict citing the specific host and evidence of compromise.
tools:
- endpoint
- identity
- web
```

## route-on-verdict
<!-- Route on final verdict -->
if~: "the impact-assessment verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-validation
unavailable: → analyst-validation (blind_spot: no-http-body-telemetry)
else: → analyst-validation

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host and revoke any session tokens or passwords used by the AI application.
```
→ analyst-validation

## analyst-validation
<!-- Analyst validation -->
```manual target=analyst
Review the cited logs, verify the injection patterns, and confirm whether the detected software is authorized and secure according to policy.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
Document the findings, update software inventory policies for AI apps, and submit tuning notes if false positives occurred.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.