Threat actors could harness a recently addressed GitHub Codespaces flaw to facilitate passive prompt injections that trick GitHub Copilot into stealthily exposing GitHub tokens through the new RoguePilot supply chain attack, SecurityWeek reports.Illicit content hidden via HTML comments could be used to inject malicious Copilot injections without alerting developers, a report from Orca Security found. Additional Codespaces features, including default VS Code retrieval of JSON schemas from the web and symbolic link preservation in repositories, could also be exploited to enable access and data exfiltration. Attackers using RoguePilot could also compromise the GITHUB_TOKEN environment variable."In our research, we demonstrated a practical chain: issue text bound to an in-environment Copilot agent, repository symlinks that reach shared runtime files, and automatic JSON schema downloads together enabled exfiltration of a Codespaces GITHUB_TOKEN and a full repository takeover," said Orca Security researchers.
Vulnerability Management, AI/ML, DevOps
Attack exploiting GitHub Codespaces flaw enables Copilot leak of GitHub tokens

An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



