Vulnerability Management, AI/ML, DevOps

Attack exploiting GitHub Codespaces flaw enables Copilot leak of GitHub tokens

Threat actors could harness a recently addressed GitHub Codespaces flaw to facilitate passive prompt injections that trick GitHub Copilot into stealthily exposing GitHub tokens through the new RoguePilot supply chain attack, SecurityWeek reports.

Illicit content hidden via HTML comments could be used to inject malicious Copilot injections without alerting developers, a report from Orca Security found. Additional Codespaces features, including default VS Code retrieval of JSON schemas from the web and symbolic link preservation in repositories, could also be exploited to enable access and data exfiltration. Attackers using RoguePilot could also compromise the GITHUB_TOKEN environment variable.

"In our research, we demonstrated a practical chain: issue text bound to an in-environment Copilot agent, repository symlinks that reach shared runtime files, and automatic JSON schema downloads together enabled exfiltration of a Codespaces GITHUB_TOKEN and a full repository takeover," said Orca Security researchers.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds