Exploitation of AI-Generated Vibe-Coded Applications
An attacker is exploiting vulnerabilities in AI-generated applications—such as missing input validation or hardcoded secrets—to gain initial access, brute-force credentials, or execute code from user-writable directories.
Based on research by ESET Research 2026-09-29 12 steps · 5 queries T1110 T1190
Brief
Why this hunt? 1000
In the article "Is that vibe coded app safe? 5 checks before you download" (https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/), ESET researchers explore the risks of applications generated by AI. This trend, known as "vibe coding," enables users to build functional software by simply describing requirements. While this accelerates development, it frequently results in code that misses critical security controls. These applications often enter the environment without formal security review or static analysis.
The primary risk involves the lack of production-grade hardening. Vibe-coded apps are often prototypes that "just work." They frequently contain vulnerabilities like hardcoded API keys, missing rate limiting on login forms, and a complete lack of input validation. Because these apps are often hosted on developer workstations or internal servers, they provide a path for attackers to gain a foothold in sensitive network segments. This hunt identifies these applications and determines if anyone is attempting to exploit them.
How the hunt flows
The first phase scopes the environment to identify where these applications exist. The first query searches the software inventory for packages and vendors linked to popular AI-generation platforms. It looks for names like Lovable, Replit, Bolt, and Cursor. This step allows the analyst to focus subsequent, more resource-intensive queries on the specific subset of hosts running these tools.
Once the analyst has a list of target hosts, the hunt moves into a parallel evidence-gathering phase. One branch queries vulnerability management data for findings on these hosts related to validation or encryption. This helps identify which AI-generated tools have known weaknesses. The second branch examines HTTP activity. It looks for traffic targeting common AI backend endpoints, such as URI paths used for prompt generation or chat interfaces. These paths are the primary targets for prompt injection attacks.
The final phase looks for signs of impact. The hunt queries for authentication spikes that indicate brute-force attempts against the application's login interfaces. Since vibe-coded apps rarely implement rate limiting, they are vulnerable to simple password guessing. Simultaneously, the hunt looks for rare process execution on these hosts. It targets processes launching from user-writable directories, such as AppData or /tmp, which might indicate that an attacker successfully exploited a file-upload or code-execution vulnerability. An analyst then evaluates the full chain to confirm an intrusion.
What the hunt cannot see
This hunt has two primary blind spots. First, standard HTTP activity logs typically do not capture the request body. If an attacker places a malicious prompt injection payload inside a POST request body rather than the URL, this hunt sees the connection but cannot see the intent. Second, the hunt depends on existing software signatures and vulnerability findings. Because vibe-coding allows for bespoke applications, some tools might use unique names or contain zero-day vulnerabilities that scanners have not yet indexed.
Steps
-
Scope hosts with AI-generated apps
Query · scopingIdentify hosts where software from AI-generation platforms is installed to narrow the hunt to relevant assets.
reads hb_software_inventorysqlSELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'What a hit looks like. A list of hosts and software packages. Silence means no known vibe-coding platforms were found in the software inventory.
-
Vulnerability findings for insecure code
Query · enrichmentNarrow the search to findings related to input validation or encryption on hosts already identified as having AI-generated apps.
reads hb_vulnerability_findingsqlSELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')What a hit looks like. Findings indicating insecure development practices on target hosts. Silence means no validation-related CVEs are currently open on those assets.
-
HTTP traffic to AI endpoints
Query · triageFind traffic targeting AI-related URI paths where prompt injection often occurs, indicating possible backend exploitation attempts.
reads hb_http_activitysqlSELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Requests to AI-specific backend paths. Silence means no tracked endpoints were accessed during the lookback window.
-
Early stage exposure analysis
Agent triageDetermine if any host shows a combination of AI apps and either known vulnerabilities or suspicious traffic patterns before looking for impact.
-
Brute force against unprotected logins
Query · detection candidateDetect failed login spikes scoped to the identified AI-app hosts, where rate-limiting is likely missing.
reads hb_auth_signinsqlSELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}What a hit looks like. Hosts or IPs showing excessive failed logins. Silence indicates no password guessing was observed on these specific hosts.
-
Rare execution from app directories
Query · baselineFind rare processes launched from user-writable paths specifically on the hosts hosting AI apps.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A process launched from a user profile on a scoped host. Silence proves no rare processes launched from these paths in the current snapshot.
-
Final impact assessment
Agent triageConsolidate the early-stage findings with follow-on brute force or suspicious process activity to confirm an intrusion chain.
-
Route on final verdict
DecisionDetermine whether to contain the host based on the high-confidence agent verdict.
-
Isolate host
Response actionContain confirmed intrusion to prevent lateral movement or data exfiltration.
-
Analyst validation
Analyst taskReview the agent's findings and verify the malicious activity.
-
Close out
Analyst taskFinalize the hunt and record improvements.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Identification of Insecure AI Apps T1190 |
Yes | scope-vibe-apps, vuln-findings |
| Exploitation of Web Vulnerabilities T1190 |
Yes | http-injection |
| Brute Force Against Unprotected Logins T1110 |
Yes | signin-brute-force |
| Malicious App Execution | Yes | rare-process-execution |
Blind spots
- Needs hb_http_activity with request body capture. Attackers can hide malicious prompts in the HTTP request body which is not captured by standard proxy or server logs. It would answer Are prompt injection payloads hidden in POST bodies?.
- Needs Source code scanning integration. Software inventory and vulnerability findings only see what is already known; new vibe-coded apps have bespoke flaws not yet indexed. It would answer Does the app contain hardcoded secrets not yet known to scanners?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
brute_force_limit | number | 20 | Threshold for login failures from a single IP to indicate brute forcing. |
injection_patterns | list[string] | /api/ai/chat, /api/generate, /v1/completions, /prompt | Specific URI paths commonly used by AI-integrated backends that are targets for injection. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Hosts to narrow the follow-on search; the analyst should populate this from the scoping step results. |
vibe_platforms | list[string] | lovable, replit, vibe, bolt.new, cursor | Keywords or vendor names associated with AI-coding platforms. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
| Web server / proxy logs | siem | network |
Source
---
analysis: A simple rule cannot link the presence of an AI-generated package to its
specific unvalidated URI paths and a subsequent brute-force spike. This hunt pivots
across inventory, vulnerabilities, HTTP, and auth logs using a phased flow to confirm
a full attack chain.
blind_spots:
- id: no-http-body-telemetry
question: Are prompt injection payloads hidden in POST bodies?
requires: hb_http_activity with request body capture
risk: Attackers can hide malicious prompts in the HTTP request body which is not
captured by standard proxy or server logs.
stage: exploit-vibe-coded-backend
- id: os-agnostic-vulnerabilities
question: Does the app contain hardcoded secrets not yet known to scanners?
requires: Source code scanning integration
risk: Software inventory and vulnerability findings only see what is already known;
new vibe-coded apps have bespoke flaws not yet indexed.
stage: vulnerability-discovery
coverage:
- stage: vulnerability-discovery
status: covered
steps:
- scope-vibe-apps
- vuln-findings
- stage: exploit-vibe-coded-backend
status: covered
steps:
- http-injection
- stage: brute-force-credential-access
status: covered
steps:
- signin-brute-force
- stage: malicious-app-installation
status: covered
steps:
- rare-process-execution
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: AI-generated applications are appearing in environments without formal
security vetting, introducing risks like missing rate-limiting and input validation;
finding these before they are exploited is a critical exposure check for modern
developer environments.
methodology: model-assisted
trigger: intel-report
hypothesis: "An attacker is exploiting vulnerabilities in AI-generated applications\u2014\
such as missing input validation or hardcoded secrets\u2014to gain initial access,\
\ brute-force credentials, or execute code from user-writable directories."
labels:
- hunt
- attack.t1190
- attack.t1110
- credential access
- discovery
- execution
- initial access
name: Exploitation of AI-Generated Vibe-Coded Applications
parameters:
brute_force_limit:
default: '20'
description: Threshold for login failures from a single IP to indicate brute forcing.
type: number
injection_patterns:
default:
- /api/ai/chat
- /api/generate
- /v1/completions
- /prompt
description: Specific URI paths commonly used by AI-integrated backends that are
targets for injection.
type: list[string]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Hosts to narrow the follow-on search; the analyst should populate
this from the scoping step results.
type: list[host]
vibe_platforms:
default:
- lovable
- replit
- vibe
- bolt.new
- cursor
description: Keywords or vendor names associated with AI-coding platforms.
from:
kind: article
observed: '2026-09-25'
ref: eset-research
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Focus on developer workstations and servers hosting internal prototypes.
Narrow the lookback if the HTTP traffic volume is high.
references:
- name: Is that vibe coded app safe? 5 checks before you download
url: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
related:
- hunt: hardcoded-secrets-in-scripts
reason: Searching for secrets in file content requires hb_file_activity with data
capture or hb_script_activity, which is a separate hunt.
relation: out-of-scope-alternative
scenario:
stages:
- name: Identification of Insecure AI Apps
observables:
- vulnerabilities in Lovable-hosted apps
- missing input validation
- hardcoded API keys
- weak encryption settings
- public-by-default access controls
slug: vulnerability-discovery
tactic: discovery
techniques:
- T1190
- name: Exploitation of Web Vulnerabilities
observables:
- malicious prompt injection
- unauthorized web requests to application endpoints
- manipulation of input fields due to missing validation
- extraction of sensitive user data from backend databases
slug: exploit-vibe-coded-backend
tactic: initial-access
techniques:
- T1190
- name: Brute Force Against Unprotected Logins
observables:
- repeated login failures without rate limiting
- automated password guessing attempts
- high volume of auth requests from single IP
- leaked session tokens
slug: brute-force-credential-access
tactic: credential-access
techniques:
- T1110
- name: Malicious App Execution
observables:
- unauthorized malware installation
- suspicious process launches from app directories
- apps requesting excessive camera or data permissions
- factory reset indicators on Android devices
slug: malicious-app-installation
tactic: execution
summary: AI-generated 'vibe coded' applications often lack fundamental security
controls like rate limiting and input validation, exposing them to brute force
and exploitation. This scenario covers the identification of these vulnerable
applications and the subsequent credential access or exploitation attempts by
malicious actors.
severity: medium
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Exploitation of AI-Generated Vibe-Coded Applications
Vibe coding allows rapid application development but often bypasses traditional security reviews, leading to critical flaws such as missing input validation and rate limiting. This hunt identifies the presence of apps from popular AI-coding platforms, detects early signs of web-based exploitation like prompt injection, and correlates these with follow-on credential access or suspicious host activity. By phasing the analysis, we distinguish between generic noise and targeted exploitation of insecurely built internal tools that lack production-grade security controls.
## scope-vibe-apps
<!-- Scope hosts with AI-generated apps -->
Identify hosts where software from AI-generation platforms is installed to narrow the hunt to relevant assets.
```sqlite target=endpoint role=scoping params=(vibe_platforms=vibe_platforms)
~~~yaml
expected: A list of hosts and software packages. Silence means no known vibe-coding
platforms were found in the software inventory.
reads:
- device_hostname
- device_uid
- package_name
- vendor_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'
```
## early-stage-parallel
<!-- Gather early exploitation evidence -->
parallel:
- → vuln-findings
- → http-injection
join: → early-triage
## vuln-findings
<!-- Vulnerability findings for insecure code -->
Narrow the search to findings related to input validation or encryption on hosts already identified as having AI-generated apps.
```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts)
~~~yaml
expected: Findings indicating insecure development practices on target hosts. Silence
means no validation-related CVEs are currently open on those assets.
reads:
- device_uid
- title
- severity
- affected_package_name
silence: evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')
```
## http-injection
<!-- HTTP traffic to AI endpoints -->
Find traffic targeting AI-related URI paths where prompt injection often occurs, indicating possible backend exploitation attempts.
```sqlite target=web role=triage params=(injection_patterns=injection_patterns, lookback_days=lookback_days)
~~~yaml
expected: Requests to AI-specific backend paths. Silence means no tracked endpoints
were accessed during the lookback window.
reads:
- device_hostname
- src_endpoint_ip
- url_full
- http_method
- url_path
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```
## early-triage
<!-- Early stage exposure analysis -->
```agent target=hunter
cite: required
context:
- scope-vibe-apps
- vuln-findings
- http-injection
max_iterations: 4
objective: Determine if any host has a combination of AI apps and either known vulnerabilities
or suspicious traffic patterns indicating a beachhead.
success_criteria: A per-host verdict on the likelihood of initial access attempts.
tools:
- endpoint
- identity
- web
```
## follow-on-parallel
<!-- Check for credential access and execution -->
parallel:
- → signin-brute-force
- → rare-process-execution
join: → impact-assessment
## signin-brute-force
<!-- Brute force against unprotected logins -->
Detect failed login spikes scoped to the identified AI-app hosts, where rate-limiting is likely missing.
```sqlite target=identity role=detection-candidate params=(lookback_days=lookback_days, brute_force_limit=brute_force_limit, scope_hosts=scope_hosts)
~~~yaml
expected: Hosts or IPs showing excessive failed logins. Silence indicates no password
guessing was observed on these specific hosts.
reads:
- dst_endpoint_name
- src_endpoint_ip
- actor_user_name
- time
- activity_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}
```
## rare-process-execution
<!-- Rare execution from app directories -->
Find rare processes launched from user-writable paths specifically on the hosts hosting AI apps.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A process launched from a user profile on a scoped host. Silence proves
no rare processes launched from these paths in the current snapshot.
prevalence:
by: device_hostname
key:
- process_name
rare_below: 3
reads:
- device_hostname
- process_name
- process_path
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')
```
## impact-assessment
<!-- Final impact assessment -->
```agent target=hunter
cite: required
context:
- early-triage
- signin-brute-force
- rare-process-execution
max_iterations: 6
objective: Determine if an attacker transitioned from exploiting a vulnerable AI app
to gaining credential access or executing code, using context from the early triage.
success_criteria: A final verdict citing the specific host and evidence of compromise.
tools:
- endpoint
- identity
- web
```
## route-on-verdict
<!-- Route on final verdict -->
if~: "the impact-assessment verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-validation
unavailable: → analyst-validation (blind_spot: no-http-body-telemetry)
else: → analyst-validation
## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host and revoke any session tokens or passwords used by the AI application.
```
→ analyst-validation
## analyst-validation
<!-- Analyst validation -->
```manual target=analyst
Review the cited logs, verify the injection patterns, and confirm whether the detected software is authorized and secure according to policy.
```
→ close-out
## close-out
<!-- Close out -->
```manual target=analyst
Document the findings, update software inventory policies for AI apps, and submit tuning notes if false positives occurred.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.