Security researchers have revealed an attack against GitHub Copilot CLI that can expose developer secrets through an attacker-controlled webpage.
This technique is called Cryptographic Context Injection (CCI). It involves hiding malicious instructions in encrypted content, which then convinces the coding agent to decrypt and run them in its runtime environment.
According to Adversa AI’s disclosure, published on October 6, 2026, researchers demonstrated the theft of a local `.env.prod` file in just 28 seconds. The attack required utilizing autopilot mode and a permissive model, rather than bypassing an interactive confirmation prompt.
The attack begins when a developer requests Copilot CLI to retrieve an external webpage. That page presents encrypted material and directs the agent to decrypt it using Python, providing two supposed decryption keys.
One key is legitimate, while the other is a template designed to prompt the agent to read specific local files and incorporate their contents into a constructed key string. This process inadvertently collects sensitive data before successful decryption occurs.
The templated key is intentionally designed to fail. Subsequently, Copilot attempts to use the valid key, which decrypts a second-stage payload instructing it to retrieve another URL for additional context.
That outbound request includes the harvested file contents as a request parameter and sends them to the attacker’s endpoint.
Researchers reported that the transcript did not identify the destination host or reveal that local data had left the machine. Instead, the agent’s final summary stated that it had “confirmed an authorized-reader endpoint.”
CCI exploits the boundary between untrusted external content and agent-generated runtime output. Instructions initially hidden as ciphertext emerge from code executed by the agent, allowing attacker-controlled text to gain apparent legitimacy.
Researchers noted that equivalent plaintext instructions were detected and rejected as prompt injection, emphasizing that encryption is central to the demonstrated attack.
Results varied across models. Microsoft’s mai-code-1.1-flash completed the attack chain in 50% of tested runs, while two GPT-5.6 models consistently refused the same payload.
On an account using Auto routing, researchers noticed that sessions were assigned to either vulnerable or resistant models without user intervention, undermining reliance solely on model refusal.
Adversa AI reported the issue to GitHub’s bug bounty program on September 17, 2026. According to the researchers, GitHub validated the behavior but did not classify it as a vulnerability or grant bounty eligibility, citing the user’s decision to fetch content from an attacker-controlled source with autonomous permissions.
The researchers confirmed that the attack chain remained reproducible as of October 1. Specific payloads were withheld from disclosure.
Recommended protective measures focus on the agent’s execution environment: record fully resolved tool arguments, correlate external content ingestion with code execution and file access, and restrict unexpected outbound destinations.
Organizations should also isolate untrusted content processing from credentials and privileged tools. In unattended workflows, new network destinations and operations outside the authorized workspace should be denied by default.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…