Research
The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching
Publication date unknown · Discovered arxiv.org
Page published
Publication date unknown · First observed: 10 Oct 2026
Coverage timeline
Single-source research — one report is available.
Why it matters
LLMLeak shows that an LLM's benign website-fetch capability can act as an air-gap-bypassing covert channel, letting malware exfiltrate data without any obvious network code, which defenders relying on network restrictions or prompt-injection filters would miss.
Researchers present LLMLeak, a covert exfiltration technique in which locally-running malware that cannot reach the internet directly abuses an LLM's legitimate web-fetching tool to leak secrets. The malicious component embeds a secret into a URL framed as needed for a benign task (e.g. library migration); when the LLM fetches it, an attacker-controlled DNS or web server receives the encoded data. Evaluation across eleven open-parameter models shows a 79.7% attack success rate, plus a case study on real-world chatbots.