---
analysis: A simple rule cannot link the presence of an AI-generated package to its
  specific unvalidated URI paths and a subsequent brute-force spike. This hunt pivots
  across inventory, vulnerabilities, HTTP, and auth logs using a phased flow to confirm
  a full attack chain.
blind_spots:
- id: no-http-body-telemetry
  question: Are prompt injection payloads hidden in POST bodies?
  requires: hb_http_activity with request body capture
  risk: Attackers can hide malicious prompts in the HTTP request body which is not
    captured by standard proxy or server logs.
  stage: exploit-vibe-coded-backend
- id: os-agnostic-vulnerabilities
  question: Does the app contain hardcoded secrets not yet known to scanners?
  requires: Source code scanning integration
  risk: Software inventory and vulnerability findings only see what is already known;
    new vibe-coded apps have bespoke flaws not yet indexed.
  stage: vulnerability-discovery
coverage:
- stage: vulnerability-discovery
  status: covered
  steps:
  - scope-vibe-apps
  - vuln-findings
- stage: exploit-vibe-coded-backend
  status: covered
  steps:
  - http-injection
- stage: brute-force-credential-access
  status: covered
  steps:
  - signin-brute-force
- stage: malicious-app-installation
  status: covered
  steps:
  - rare-process-execution
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: AI-generated applications are appearing in environments without formal
    security vetting, introducing risks like missing rate-limiting and input validation;
    finding these before they are exploited is a critical exposure check for modern
    developer environments.
  methodology: model-assisted
  trigger: intel-report
hypothesis: "An attacker is exploiting vulnerabilities in AI-generated applications\u2014\
  such as missing input validation or hardcoded secrets\u2014to gain initial access,\
  \ brute-force credentials, or execute code from user-writable directories."
labels:
- hunt
- attack.t1190
- attack.t1110
- credential access
- discovery
- execution
- initial access
name: Exploitation of AI-Generated Vibe-Coded Applications
parameters:
  brute_force_limit:
    default: '20'
    description: Threshold for login failures from a single IP to indicate brute forcing.
    type: number
  injection_patterns:
    default:
    - /api/ai/chat
    - /api/generate
    - /v1/completions
    - /prompt
    description: Specific URI paths commonly used by AI-integrated backends that are
      targets for injection.
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Hosts to narrow the follow-on search; the analyst should populate
      this from the scoping step results.
    type: list[host]
  vibe_platforms:
    default:
    - lovable
    - replit
    - vibe
    - bolt.new
    - cursor
    description: Keywords or vendor names associated with AI-coding platforms.
    from:
      kind: article
      observed: '2026-09-25'
      ref: eset-research
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on developer workstations and servers hosting internal prototypes.
  Narrow the lookback if the HTTP traffic volume is high.
references:
- name: Is that vibe coded app safe? 5 checks before you download
  url: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
related:
- hunt: hardcoded-secrets-in-scripts
  reason: Searching for secrets in file content requires hb_file_activity with data
    capture or hb_script_activity, which is a separate hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Identification of Insecure AI Apps
    observables:
    - vulnerabilities in Lovable-hosted apps
    - missing input validation
    - hardcoded API keys
    - weak encryption settings
    - public-by-default access controls
    slug: vulnerability-discovery
    tactic: discovery
    techniques:
    - T1190
  - name: Exploitation of Web Vulnerabilities
    observables:
    - malicious prompt injection
    - unauthorized web requests to application endpoints
    - manipulation of input fields due to missing validation
    - extraction of sensitive user data from backend databases
    slug: exploit-vibe-coded-backend
    tactic: initial-access
    techniques:
    - T1190
  - name: Brute Force Against Unprotected Logins
    observables:
    - repeated login failures without rate limiting
    - automated password guessing attempts
    - high volume of auth requests from single IP
    - leaked session tokens
    slug: brute-force-credential-access
    tactic: credential-access
    techniques:
    - T1110
  - name: Malicious App Execution
    observables:
    - unauthorized malware installation
    - suspicious process launches from app directories
    - apps requesting excessive camera or data permissions
    - factory reset indicators on Android devices
    slug: malicious-app-installation
    tactic: execution
  summary: AI-generated 'vibe coded' applications often lack fundamental security
    controls like rate limiting and input validation, exposing them to brute force
    and exploitation. This scenario covers the identification of these vulnerable
    applications and the subsequent credential access or exploitation attempts by
    malicious actors.
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Exploitation of AI-Generated Vibe-Coded Applications

Vibe coding allows rapid application development but often bypasses traditional security reviews, leading to critical flaws such as missing input validation and rate limiting. This hunt identifies the presence of apps from popular AI-coding platforms, detects early signs of web-based exploitation like prompt injection, and correlates these with follow-on credential access or suspicious host activity. By phasing the analysis, we distinguish between generic noise and targeted exploitation of insecurely built internal tools that lack production-grade security controls.

## scope-vibe-apps
<!-- Scope hosts with AI-generated apps -->
Identify hosts where software from AI-generation platforms is installed to narrow the hunt to relevant assets.

```sqlite target=endpoint role=scoping params=(vibe_platforms=vibe_platforms)
~~~yaml
expected: A list of hosts and software packages. Silence means no known vibe-coding
  platforms were found in the software inventory.
reads:
- device_hostname
- device_uid
- package_name
- vendor_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'
```

## early-stage-parallel
<!-- Gather early exploitation evidence -->
parallel:
- → vuln-findings
- → http-injection
join: → early-triage

## vuln-findings
<!-- Vulnerability findings for insecure code -->
Narrow the search to findings related to input validation or encryption on hosts already identified as having AI-generated apps.

```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts)
~~~yaml
expected: Findings indicating insecure development practices on target hosts. Silence
  means no validation-related CVEs are currently open on those assets.
reads:
- device_uid
- title
- severity
- affected_package_name
silence: evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')
```

## http-injection
<!-- HTTP traffic to AI endpoints -->
Find traffic targeting AI-related URI paths where prompt injection often occurs, indicating possible backend exploitation attempts.

```sqlite target=web role=triage params=(injection_patterns=injection_patterns, lookback_days=lookback_days)
~~~yaml
expected: Requests to AI-specific backend paths. Silence means no tracked endpoints
  were accessed during the lookback window.
reads:
- device_hostname
- src_endpoint_ip
- url_full
- http_method
- url_path
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-triage
<!-- Early stage exposure analysis -->
```agent target=hunter
cite: required
context:
- scope-vibe-apps
- vuln-findings
- http-injection
max_iterations: 4
objective: Determine if any host has a combination of AI apps and either known vulnerabilities
  or suspicious traffic patterns indicating a beachhead.
success_criteria: A per-host verdict on the likelihood of initial access attempts.
tools:
- endpoint
- identity
- web
```

## follow-on-parallel
<!-- Check for credential access and execution -->
parallel:
- → signin-brute-force
- → rare-process-execution
join: → impact-assessment

## signin-brute-force
<!-- Brute force against unprotected logins -->
Detect failed login spikes scoped to the identified AI-app hosts, where rate-limiting is likely missing.

```sqlite target=identity role=detection-candidate params=(lookback_days=lookback_days, brute_force_limit=brute_force_limit, scope_hosts=scope_hosts)
~~~yaml
expected: Hosts or IPs showing excessive failed logins. Silence indicates no password
  guessing was observed on these specific hosts.
reads:
- dst_endpoint_name
- src_endpoint_ip
- actor_user_name
- time
- activity_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}
```

## rare-process-execution
<!-- Rare execution from app directories -->
Find rare processes launched from user-writable paths specifically on the hosts hosting AI apps.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A process launched from a user profile on a scoped host. Silence proves
  no rare processes launched from these paths in the current snapshot.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 3
reads:
- device_hostname
- process_name
- process_path
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\appdata\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## impact-assessment
<!-- Final impact assessment -->
```agent target=hunter
cite: required
context:
- early-triage
- signin-brute-force
- rare-process-execution
max_iterations: 6
objective: Determine if an attacker transitioned from exploiting a vulnerable AI app
  to gaining credential access or executing code, using context from the early triage.
success_criteria: A final verdict citing the specific host and evidence of compromise.
tools:
- endpoint
- identity
- web
```

## route-on-verdict
<!-- Route on final verdict -->
if~: "the impact-assessment verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-validation
unavailable: → analyst-validation (blind_spot: no-http-body-telemetry)
else: → analyst-validation

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host and revoke any session tokens or passwords used by the AI application.
```
→ analyst-validation

## analyst-validation
<!-- Analyst validation -->
```manual target=analyst
Review the cited logs, verify the injection patterns, and confirm whether the detected software is authorized and secure according to policy.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
Document the findings, update software inventory policies for AI apps, and submit tuning notes if false positives occurred.
```
→ end
