Skip to content
MediumNewsLLM-specific

Encrypted instructions trick Copilot CLI into spilling developer secrets

Published
Record updated
View JSON

Summary

Adversa AI researchers described Cryptographic Context Injection (CCI), a technique that hides malicious instructions inside encrypted content so GitHub Copilot CLI treats them as trusted context. In a demonstration, Copilot read a ".env.prod" file and sent its contents to an attacker-controlled endpoint in 28 seconds without confirmation. The attack requires autopilot mode and a model willing to execute the decrypted instructions, and GitHub declined to treat it as a vulnerability.