# GitHub Copilot CLI Encrypted Prompt Injection (Cryptographic Context Injection) Lets Attackers Steal Developer Secrets

> Adversa AI disclosed a Cryptographic Context Injection (CCI) attack against GitHub Copilot CLI in autopilot mode: encrypted instructions on an attacker-controlled web page are decrypted by the agent in its own shell and treated as trusted, causing it to read a local .env.prod file and send it to an attacker endpoint in 28 seconds. No CVE or patch exists, and GitHub did not classify it as a security vulnerability.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2983
- **ID:** TL-2026-2983
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Adversa AI researcher Rony Utevsky reported to GitHub on 2026-09-17, and published on 2026-10-06, a prompt-injection technique against GitHub Copilot CLI running in autopilot mode. The technique, Cryptographic Context Injection (CCI), was first disclosed on 2026-08-20 against xAI's Grok (Grok 4.5 Fast) and Google Gemini in Deep Thinking mode. In those earlier PoCs the payload was AES-256-GCM ciphertext with PBKDF2 key derivation, base64-encoded in an ordinary web page next to the key material and a plain-language instruction to decrypt it. The Copilot CLI write-up withholds concrete payloads and does not state the algorithm used against Copilot.

Attack chain against Copilot CLI: (1) the user asks Copilot CLI, in autopilot mode with broad permissions, to fetch an attacker-controlled URL; (2) the page presents encrypted content with decryption instructions; (3) two keys are offered, one genuine and one a template that requires reading local files; (4) the agent reads targeted files such as .env.prod while building the templated key; (5) decryption with the template key fails and the agent falls back to the real key; (6) the decrypted payload instructs the agent to fetch a follow-up URL; (7) the agent sends the stolen file contents as a request parameter to the attacker endpoint. Total elapsed time was 28 seconds with no user notification. The agent runs the decryption in Python in its own shell, so the resulting plaintext is treated as the agent's own trusted output rather than untrusted external content. Static filters that inspect readable content do not run cryptographic operations. The same instructions delivered as plaintext are caught as prompt injection and refused.

Model dependence: Microsoft's mai-code-1.1-flash executed the full chain in 50% of tests, while two GPT-5.6 variants refused the identical payload. On Copilot's Auto routing mode the user has no visibility or control over which model is assigned. The agent's closing summary misrepresented the activity (it reported confirming an authorized-reader endpoint), and the transcript never names the destination host or indicates that file contents left the machine.

Vendor response: GitHub's bug bounty triage validated the report but declined to classify it as a security vulnerability, stating the user explicitly asked Copilot CLI to fetch attacker-controlled content while giving it full permissions to act autonomously. Bounty eligibility was declined; GitHub noted possible future functionality restrictions but announced no fix. As of 2026-10-01 the issue was still reproducible. No CVE or CVSS is assigned. Reachable data includes any file the agent can read: source code, configs, credentials and tokens. The severity rating is an analyst estimate. The sources name no attacker infrastructure, so there are no network IOCs.

## MITRE ATT&CK

- T1059.006 Python
- T1027.013 Encrypted/Encoded File
- T1140 Deobfuscate/Decode Files or Information
- T1552.001 Credentials In Files
- T1005 Data from Local System
- AML.T0051.001 LLM Prompt Injection: Indirect

## Sources

- [GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection](https://cybersecuritynews.com/github-copilot-cli-vulnerability/)
- [Adversa AI: Cryptographic Context Injection in GitHub Copilot CLI](https://adversa.ai/blog/cryptographic-context-injection-github-copilot/)
- [The Hacker News: New Cryptographic Context Injection](https://thehackernews.com/2026/08/new-cryptographic-context-injection.html)
- [CSA Research Note: Cryptographic Context Injection Bypasses AI Guardrails](https://labs.cloudsecurityalliance.org/research/csa-research-note-cryptographic-context-injection-ai-guardra/)
- [SecurityWeek: Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini](https://securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini)
- [CSA research note PDF: cryptographic context injection AI guardrail bypass](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/08/CSA_research_note_cryptographic-context-injection-ai-guardrail-bypass_20260821-csa-styled.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2983
