ChatGPT Outputs Malicious Link Prompting PowerShell Hijack

Ok-Combination3165 · reddit · 2026-08-07

A Reddit user reported that ChatGPT provided a malicious link (safepage-gpt.com) in its response. The website presents a fake Cloudflare verification page, tricking users into pressing Win+R and automatically copying a malicious PowerShell script to the clipboard.

The script attempts to bypass execution policies and download further malicious code from a remote server. Fortunately, the user identified the scam and did not execute the command. This highlights a significant vulnerability in how LLMs handle link generation and content safety filtering.

Original post →

More from Safety

Safety channel →