Research

The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching

Page published

Publication date unknown · First observed: 10 Oct 2026

Coverage timeline

10 Oct 2026arxiv.orgobservedprimary

Single-source research — one report is available.

Why it matters

LLMLeak shows that an LLM's benign website-fetch capability can act as an air-gap-bypassing covert channel, letting malware exfiltrate data without any obvious network code, which defenders relying on network restrictions or prompt-injection filters would miss.

Researchers present LLMLeak, a covert exfiltration technique in which locally-running malware that cannot reach the internet directly abuses an LLM's legitimate web-fetching tool to leak secrets. The malicious component embeds a secret into a URL framed as needed for a benign task (e.g. library migration); when the LLM fetches it, an attacker-controlled DNS or web server receives the encoded data. Evaluation across eleven open-parameter models shows a 79.7% attack success rate, plus a case study on real-world chatbots.