Training-free Lexical Backdoor Attacks on Language Models