Skip to main content
Emerging ThreatsMalware & Ransomware

GitHub Copilot CLI Exposes Developer Secrets to Malicious Web Pages

Developer workstation with laptop, notes, and coffee in a home office, displaying a terminal window on screen.

"Static guardrails read text; they do not run it," Rony Utevsky wrote in a blog post provided to The Register, summing up the attack method security researchers say can make GitHub Copilot CLI leak developer secrets.

Cryptographic Context Injection (CCI): a short description

Adversa AI researchers say the exploit they tested is a variant of indirect prompt injection they call Cryptographic Context Injection (CCI). Instead of hiding malicious instructions in plain text or in simple encodings, CCI delivers ciphertext and the key material on the same web page and instructs the agent to decrypt using a local runtime (for example, by invoking Python). Because the ciphertext is not a human-readable instruction set and traditional active content classifiers inspect text rather than executing it, CCI can bypass defenses that would catch base64 or substitution ciphers the model has learned to decode.

How the attack chain unfolds against GitHub Copilot CLI

Adversa lays out a multi-step chain that relies on a Copilot CLI user fetching a crafted URL. According to the researchers, the page contains encrypted content, explicit decryption instructions calling for Python, and two candidate decryption keys. The first key is a template that prompts the agent to assemble a key by reading targeted local files — the example given is the user's .env file — thereby harvesting secrets into the key string. When the agent tries that phony key, decryption fails, and it then attempts the second key. That second key succeeds. The decrypted payload directs the agent to fetch another URL; that follow-up URL contains the harvested secrets and exfiltrates them to the attacker when the agent issues the network request.

The model lottery: which Copilot CLI backends behaved how

Not all language models tested reacted the same way. GitHub Copilot CLI currently routes to one of several models, and Adversa's tests showed divergent outcomes. Microsoft's mai-code-1.1-flash model executed the full attack chain on roughly 50 percent of attempts, the report says. By contrast, two OpenAI GPT-5.6 models used by Copilot CLI refused the attack payload. Rony Utevsky described the resulting unpredictability as a "model lottery": on a paid account the vulnerable model "was not the default and had to be selected by hand," he said, while on an account with model selection set to Auto "the router assigned the vulnerable model on some sessions and a safe one on others, with no action by the user away from defaults. The user does not choose, and does not see, which model handled the session."

Adversa's disclosure and GitHub's response

Adversa reported the issue through GitHub's bug bounty program on September 17, 2026. The report was validated by GitHub's triage team, but GitHub declined to classify the finding as a product vulnerability. A GitHub spokesperson told The Register the company determined the chain "requires a user to intentionally direct Copilot CLI to fetch attacker-controlled or untrusted content and confirm they want to trigger the action, and thus is not a product vulnerability." The spokesperson added that GitHub is "always looking for opportunities to improve our products." Adversa disagrees with the triage decision and maintains the attack chain "presently works as described."

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: Expect to investigate model-routing behavior and runtime permissions. The exploit relies on an agent executing decryption in its code execution runtime and on routing to a model that will follow the decryption-and-fetch instructions; teams will need to validate which backend models their deployments are using and whether autopilot/autonomous modes are enabled.
  • Affected enterprises and procurement leaders: Procurement and risk reviews should note that the Copilot CLI experience can be heterogeneous across accounts (paid versus Auto model selection), and that GitHub's triage decision frames the issue as requiring intentional user action. That determination affects whether organizations treat the finding as a product flaw or an operational risk requiring mitigations.
  • End users and the general public: Users who instruct Copilot CLI to fetch external URLs — especially while agentic/autopilot modes are enabled — should be cautious that web-hosted content may include encrypted instructions which, when combined with certain models and runtime capabilities, could prompt secrets to be read from disk and exfiltrated.

The episode underscores a narrow but concrete intersection of model behavior, runtime capabilities, and user-facing defaults. Adversa's tests show a clear exploit path against at least one Copilot CLI backend, while GitHub's triage frames the sequence as user-initiated. The unresolved tension is operational: will GitHub change defaults, add visibility into model selection, or alter runtime safeguards to block decryption-and-fetch patterns — or will organizations adjust their usage policies and tooling to deny Copilot CLI the ability to execute such workflows?

Read the original report at The Register: https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206