Adversa AI reported that GitHub Copilot CLI could leak developer secrets through Cryptographic Context Injection (CCI), an indirect prompt-injection technique that hides malicious instructions in encrypted web content. In the demonstrated attack, Copilot CLI running in autopilot mode reads local secrets while constructing a fake decryption key, decrypts the malicious instructions using a working key, and sends the secrets through an attacker-directed URL request. Microsoft’s mai-code-1.1-flash model completed the attack chain in 50 percent of tested attempts, while two tested OpenAI GPT-5.6 models refused the payload. Automatic model routing reportedly selected vulnerable or resistant models without revealing the selection to users.
The finding follows a separate PromptArmor report describing GitHub Copilot CLI downloading and executing malware, underscoring the risks of allowing coding agents to act on untrusted content. Adversa disclosed its finding to GitHub on September 17, 2026; GitHub declined to classify it as a product vulnerability, arguing that fetching untrusted content and confirming the action constituted user consent. Organizations using Copilot CLI should restrict agents’ access to secrets, limit unattended execution and outbound requests, and avoid treating user approval or automatic model selection as reliable protection against indirect prompt injection.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Adversa AI submitted the Cryptographic Context Injection finding through GitHub's bug bounty program.
GitHub Copilot CLI was previously reported as susceptible to indirect prompt injection earlier in 2026.
According to Adversa AI, GitHub's triage team validated the finding but declined to classify it as a product vulnerability, citing the user's intentional request for untrusted content and confirmation of the action. Adversa AI disputed that assessment and maintained that the attack chain continued to work.
Microsoft's mai-code-1.1-flash completed the attack chain in 50 percent of Adversa AI's tests, while both tested OpenAI GPT-5.6 models refused the payload. Automatic routing selected vulnerable or resistant models across sessions without revealing the selection to the user.
Adversa AI identified an attack in which Copilot CLI, operating in autopilot mode, processes an attacker-controlled page containing encrypted instructions. A fake decryption-key template induces local secret collection, while a working key reveals instructions that exfiltrate those secrets through a URL request.
Cryptographic Context Injection was identified in Grok approximately two months before the Copilot CLI report. Adversa AI subsequently described the Copilot CLI issue as the same vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcetheregister.com
Open sourceadversa.ai
Open sourcepromptarmor.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.