A nearly undetectable LLM attack needs only a handful of poisoned samples