# Salt Labs hijacks the Manus AI agent with one email by encoding a prompt injection in JSFuck

> Salt Labs reported on 1 October 2026 that an obfuscated email made the Manus agent run code and open a reverse shell; the guardrail fired only after execution. The flaw is fixed.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/news/manus-ai-agent-hijacked-single-email-jsfuck-salt-labs

Researchers at Salt Labs published on 1 October 2026 an account of how they bypassed the prompt-injection protections of the Manus AI agent and achieved code execution through a single email [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/). SC Media, citing TechRadar, also covered the research and notes that the specific flaw has since been patched through a bug bounty programme [[2]](https://www.scworld.com/brief/researchers-bypass-ai-agent-protections-with-javascript-obfuscation). The case is relevant to Mac users who connect an AI agent to their mailbox and other accounts.

## Background

A prompt injection places instructions in content that an AI agent reads, so that the agent treats them as commands. Salt Labs chose the Gmail integration as a target because email is the primary identity provider for many accounts. According to the write-up, the agent processed email in a cloud sandbox, using tooling based on the Model Context Protocol and the user's OAuth token [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/).

## What the research describes

The researchers report that a plain shell-command injection was detected and blocked by the platform's guardrails, and that a Base64-encoded variant was also detected. They then encoded the payload in JSFuck, an unusual way of writing JavaScript with a very small character set, and the email asked the agent to decode it using Node.js. The agent invoked the Node.js runtime and executed arbitrary JavaScript in its server-side environment [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/).

The payload was then extended to run system commands inside the sandbox and to establish a reverse shell to attacker infrastructure. From there they reached the Gmail OAuth token, the tool interface and the credentials of connected services, with potential access to services such as Google Drive and GitHub [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/). The central finding is a timing gap: the guardrail detected the attack, but "after the code had already run" [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/). SC Media summarises the lesson as: prompt inspection is necessary but not sufficient, and protection must extend to the actions an agent takes across tools, APIs and systems [[2]](https://www.scworld.com/brief/researchers-bypass-ai-agent-protections-with-javascript-obfuscation).

The write-up states that the specific flaw was submitted through Meta's bug bounty programme and has been resolved and is no longer exploitable. It gives no disclosure timeline [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/).

> FireAI, the on-device firewall for macOS developed by HisnLabs, includes an Agent profile that learns where an AI agent normally connects and flags a first-ever destination. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

In this case the code ran in the vendor's cloud sandbox, not on a Mac, so the exposure was the tokens and connected accounts that the agent held [[1]](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/). The general point applies to local agents as well: content that an agent reads can carry instructions, and a defence that only inspects the prompt can act too late.

## Recommendations

1. Connect an AI agent only to the accounts it needs, and prefer read-only access where the service offers it.
2. Review the connected services and tokens of each agent periodically and revoke those that are not in use.
3. Treat any email, web page or document an agent reads as untrusted input.
4. Prefer agents whose actions require approval for commands, file changes and new network destinations.
5. Watch which network destinations an agent on the Mac contacts, and investigate a destination that is new.

## Relevance to FireAI

FireAI's [Agent profile](https://hisnlabs.com/en/docs/agent-profile) recognises AI agents on a Mac, learns where each normally connects, and flags a first-ever destination or an upload spike for review, using only host names and byte counts. In its stricter mode it blocks a new destination until the user allows it.

FireAI does not run in a vendor's cloud, so it cannot see or stop what happened inside the Manus sandbox. It does not read emails or prompts, does not decide whether an instruction is an injection, and does not read the inside of encrypted connections. It acts on the network side of agents that run on the Mac.

> A local agent that is told to send data somewhere new has to open a connection. FireAI asks before a destination without a rule is contacted and keeps the history. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The technical account is the researchers' own, read here through a Security Boulevard republication; this item did not independently reproduce it. The sources do not report exploitation by anyone other than the researchers, and the date of the fix is not given. SC Media states that creative bypasses beyond JSFuck are likely to emerge [[2]](https://www.scworld.com/brief/researchers-bypass-ai-agent-protections-with-javascript-obfuscation).

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [Salt Labs via Security Boulevard, 1 October 2026: How We Hijacked an AI Agent With a Single Email](https://securityboulevard.com/2026/10/how-we-hijacked-an-ai-agent-with-a-single-email/)
- [SC Media, 3 October 2026: Researchers bypass AI agent protections with JavaScript obfuscation](https://www.scworld.com/brief/researchers-bypass-ai-agent-protections-with-javascript-obfuscation)
