Cyber Security News

GitHub Copilot CLI Flaw Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

Security researchers have revealed an attack against GitHub Copilot CLI that can expose developer secrets through an attacker-controlled webpage.

This technique is called Cryptographic Context Injection (CCI). It involves hiding malicious instructions in encrypted content, which then convinces the coding agent to decrypt and run them in its runtime environment.

According to Adversa AI’s disclosure, published on October 6, 2026, researchers demonstrated the theft of a local `.env.prod` file in just 28 seconds. The attack required utilizing autopilot mode and a permissive model, rather than bypassing an interactive confirmation prompt.

GitHub Copilot CLI Flaw

The attack begins when a developer requests Copilot CLI to retrieve an external webpage. That page presents encrypted material and directs the agent to decrypt it using Python, providing two supposed decryption keys.

One key is legitimate, while the other is a template designed to prompt the agent to read specific local files and incorporate their contents into a constructed key string. This process inadvertently collects sensitive data before successful decryption occurs.

The templated key is intentionally designed to fail. Subsequently, Copilot attempts to use the valid key, which decrypts a second-stage payload instructing it to retrieve another URL for additional context.

That outbound request includes the harvested file contents as a request parameter and sends them to the attacker’s endpoint.

Researchers reported that the transcript did not identify the destination host or reveal that local data had left the machine. Instead, the agent’s final summary stated that it had “confirmed an authorized-reader endpoint.”

CCI exploits the boundary between untrusted external content and agent-generated runtime output. Instructions initially hidden as ciphertext emerge from code executed by the agent, allowing attacker-controlled text to gain apparent legitimacy.

Researchers noted that equivalent plaintext instructions were detected and rejected as prompt injection, emphasizing that encryption is central to the demonstrated attack.

Results varied across models. Microsoft’s mai-code-1.1-flash completed the attack chain in 50% of tested runs, while two GPT-5.6 models consistently refused the same payload.

On an account using Auto routing, researchers noticed that sessions were assigned to either vulnerable or resistant models without user intervention, undermining reliance solely on model refusal.

Adversa AI reported the issue to GitHub’s bug bounty program on September 17, 2026. According to the researchers, GitHub validated the behavior but did not classify it as a vulnerability or grant bounty eligibility, citing the user’s decision to fetch content from an attacker-controlled source with autonomous permissions.

The researchers confirmed that the attack chain remained reproducible as of October 1. Specific payloads were withheld from disclosure.

Recommended protective measures focus on the agent’s execution environment: record fully resolved tool arguments, correlate external content ingestion with code execution and file access, and restrict unexpected outbound destinations.

Organizations should also isolate untrusted content processing from credentials and privileged tools. In unattended workflows, new network destinations and operations outside the authorized workspace should be denied by default.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

1 hour ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

2 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

3 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

3 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

4 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

5 hours ago