Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

"Zombie instructions" on websites can cause GitHub Copilot CLI to leak developer data

Cybersecurity researchers at Adversa AI have discovered a critical vulnerability in GitHub Copilot CLI. Under certain conditions, the tool could be forced to steal and send private keys, passwords, and configuration files (e.g., .env) to attackers.

Leave a comment
"Zombie instructions" on websites can cause GitHub Copilot CLI to leak developer data

Cybersecurity researchers at Adversa AI have discovered a critical vulnerability in GitHub Copilot CLI. Under certain conditions, the tool could be forced to steal and send private keys, passwords, and configuration files (e.g., .env) to attackers.

The attack is based on the Cryptographic Context Injection (CCI) method, the same one found in the Grok neural network two months earlier, The Register reports .

How the attack works

The threat is implemented when a developer runs Copilot CLI in autopilot mode and asks the tool to read the content of a specific web page.

  • The attacker places instructions on the site encrypted with a strong cipher. Standard security filters and classifiers do not see the encrypted text as a threat (unlike simple encoding types like Base64).

  • The AI ​​agent is instructed to decrypt the text using Python. The first decryption key is a fake one. The instruction forces the AI ​​to generate this key by pulling data from the developer's local files (e.g., secrets from .env). The attempt to decrypt with this "key" fails.

  • The AI ​​takes the second (real) key, successfully decrypts the text, and receives a new command — to go to the next URL to “get context.” However, this URL already contains a generated string with stolen secrets, which are automatically sent to the hacker’s server when requested.

Model lottery: which neural networks are at risk?

The success of the attack depends on which model Copilot CLI uses in a particular session:

  • mai-code-1.1-flash (Microsoft's own model) - proved to be vulnerable and successfully executed the entire attack chain in 50% of cases;

  • OpenAI GPT-5.6 (two modifications) - proved to be stable and refused to execute malicious commands.

Researchers note that if the model selection in the account settings is set to "Auto", the developer does not even know which model is processing his request at that moment, which turns the work into a real lottery.

GitHub's response: "This is not a product vulnerability"

The Adversa AI team reported the issue to GitHub via the Bug Bounty program on September 17, 2026. GitHub specialists confirmed the reproduction of the issue, but refused to recognize it as a system vulnerability.

A GitHub representative stated: “This requires the user to knowingly direct the Copilot CLI to download maliciously controlled or untrusted content and confirm this action. So, this is not a vulnerability in the product itself. However, we are always looking for ways to improve protection.”

Adversa AI disagrees with this assessment and warns: since GitHub refused to release a patch, the attack remains fully operational for all users who run the tool in autopilot mode.

Hackers steal data through fake "I'm not a robot" verification. CERT-UA detects large-scale cyberattack
Hackers steal data through fake "I'm not a robot" verification. CERT-UA detects large-scale cyberattack
On the topic
Hackers steal data through fake "I'm not a robot" verification. CERT-UA detects large-scale cyberattack
A vulnerability was discovered in ChatGPT that allowed for stealthy data theft from Gmail and Google Drive
A vulnerability was discovered in ChatGPT that allowed data to be silently stolen from Gmail and Google Drive
On the topic
A vulnerability was discovered in ChatGPT that allowed data to be silently stolen from Gmail and Google Drive
40% of newly encrypted apps expose users' confidential data and have no safeguards at all. What conclusions did experts come to?
40% of newly encrypted apps expose users' confidential data and have no safeguards at all. What conclusions did experts come to?
On the topic
40% of newly encrypted apps expose users' confidential data and have no safeguards at all. What conclusions did experts come to?
AI agents leaked over 13,000 private company images to GitHub for code writing
AI agents leaked over 13,000 private company images to GitHub for code writing
On the topic
AI agents leaked over 13,000 private company images to GitHub for code writing
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Чи може AI замінити кодерів: ось які завдання готові віддати штучному інтелекту українські айтішники
Чи може AI замінити кодерів: ось які завдання готові віддати штучному інтелекту українські айтішники
Чи може AI замінити кодерів: ось які завдання готові віддати штучному інтелекту українські айтішники
GitHub запровадив розширення Copilot, що за допомогою штучного інтелекту може писати код вслід за вже написаним рядком.  І це не перша розробка в цьому полі. Ми запитали розробників, керівників, кодерів та всіх, хто долучений до цієї теми, чи може штучний інтелект замінити людину, що можна довірити машині, та чи не підштовхне це працедавців до звільнень. На опитання відгукнулись 25 респондентів і їх відповіді нас зацікавили.
Штучний інтелект допомагатиме розробникам кодувати. GitHub запустив сервіс Copilot на AI за $10 на місяць
Штучний інтелект допомагатиме розробникам кодувати. GitHub запустив сервіс Copilot на AI за $10 на місяць
Штучний інтелект допомагатиме розробникам кодувати. GitHub запустив сервіс Copilot на AI за $10 на місяць
Спеціалісти GitHub від Microsoft розробили та запустили сервіс Copilot, що за допомогою штучного інтелекту додає пропозиції коду на основі попередньої строки або коментаря. Версія загальнодоступна для всіх розробників за $10 на місяць або $100 на рік. 
Сервіс для IT-проєктів GitHub почав блокування користувачів з рф
Сервіс для IT-проєктів GitHub почав блокування користувачів з рф
Сервіс для IT-проєктів GitHub почав блокування користувачів з рф
Українському інженеру SoftServe запропонували проєкт зі створення аналога Zoom і Git платформ для рф. Як думаєте, що він відповів?
Українському інженеру SoftServe запропонували проєкт зі створення аналога Zoom і Git платформ для рф. Як думаєте, що він відповів?
Українському інженеру SoftServe запропонували проєкт зі створення аналога Zoom і Git платформ для рф. Як думаєте, що він відповів?

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.