
GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page.
Security researchers at Adversa AI said the new attack technique, dubbed Cryptographic Context Injection (CCI), hides malicious instructions inside encrypted content. These instructions are treated as trusted context when Copilot CLI decrypts the content using its own code-execution environment, allowing them to influence what the agent does next.
In a demonstration, Adversa researchers got Copilot to read a “.env.prod” file containing secrets and send its contents to an attacker-controlled endpoint. “Full chain: 28 seconds, no confirmation, and no point in the transcript that names the destination host or indicates that file contents left the machine,” the researcher said in a blog post.
