Encrypted instructions trick Copilot CLI into spilling developer secrets

Tags:

GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page.

Security researchers at Adversa AI said the new attack technique, dubbed Cryptographic Context Injection (CCI), hides malicious instructions inside encrypted content. These instructions are treated as trusted context when Copilot CLI decrypts the content using its own code-execution environment, allowing them to influence what the agent does next.

In a demonstration, Adversa researchers got Copilot to read a “.env.prod” file containing secrets and send its contents to an attacker-controlled endpoint. “Full chain: 28 seconds, no confirmation, and no point in the transcript that names the destination host or indicates that file contents left the machine,” the researcher said in a blog post.

According to Adversa, the attack is not a universal one-click compromise as it requires Copilot CLI to be running in autopilot mode and a model willing to execute the decrypted instructions. GitHub has validated the finding but declined to treat it as a vulnerability, saying the user had explicitly asked Copilot to fetch attacker-controlled content while giving full permissions to act autonomously.

“They noted they may make the functionality stricter in the future but had nothing to announce, and ruled the report ineligible for the GitHub bug bounty program,” Adversa said. The researchers disputed that assessment, arguing that it does not explain why Copilot rejects the same instructions when presented in plaintext but accepts them after they have been encrypted and decrypted within its execution environment.

GitHub did not immediately respond to CSO’s request for comment.

Encryption makes the attack possible

An attack could begin with a user running Copilot CLI and asking it to fetch a URL, the researchers explained. The page would contain encrypted instructions that the agent would then be asked to decrypt using two candidate keys.

While one of those keys is a legitimate key, the other is a template that can only be completed by reading files from the local machine. The attack chain continues with the agent attempting to prepare both keys by reading targeted files and adding their contents to the template.

This reading of the file itself is the actual theft.

The reconstructed key fails decryption, though it serves its intended purpose, after which Copilot uses the legitimate key. The decrypted instructions then tell it to make another web request, carrying the previously collected file contents to the attacker’s endpoint.

The model decides if the attack works

Copilot’s model selection can change the outcome, though.

Researchers said Microsoft’s mai-code-1.1-flash model executed the complete chain in 50% of their runs, while two GPT-5.6 models offered through Copilot consistently refused the same payload. With Model selection set to Auto, Adversa says the vulnerable model was assigned in some sessions without the user choosing or seeing which model was handling the workflow.

While GitHub refuses to call it a flaw or fix the underlying behavior, Adversa advises defenders to look for any suspicious sequence of actions around an encrypted payload: untrusted web content enters the agent, code executes, local files are read, and the agent subsequently makes an unrelated outbound connection.

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *